Vulnerabilities > CVE-2021-38621 - Unspecified vulnerability in Netless Flat Server

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
netless
critical

Summary

The remove API in v1/controller/cloudStorage/alibabaCloud/remove/index.ts in netless Agora Flat Server before 2021-07-30 mishandles file ownership.

Vulnerable Configurations

Part Description Count
Application
Netless
1