High severity7.5NVD Advisory· Published Dec 24, 2021· Updated Jun 17, 2026
CVE-2021-20874
CVE-2021-20874
Description
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:groupsession:groupsession:*:*:*:*:cloud:*:*:*+ 2 more
- cpe:2.3:a:groupsession:groupsession:*:*:*:*:cloud:*:*:*range: <=5.1.1
- cpe:2.3:a:groupsession:groupsession:*:*:*:*:free:*:*:*range: <=5.1.1
- cpe:2.3:a:groupsession:groupsession:*:*:*:*:zion:*:*:*range: <=5.1.1
- Range: <=5.1.1
- Range: <=5.1.1
- Range: <=5.1.1
- Japan Total System Co.,Ltd./GroupSession Free edition, GroupSession byCloud, GroupSession ZIONv5Range: GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier
Patches
Vulnerability mechanics
References
2- groupsession.jp/info/info-news/security20211220nvdVendor Advisory
- jvn.jp/en/jp/JVN79798166/index.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.