LiveActive security incident?Get immediate response
CVE Record

CVE-2021-31590: PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect acc...

PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect access control. With a valid JSON Webtoken that is used for authentication and authorization, a user can keep his admin privileges even if he is downgraded to the "user" privilege. Even after a user's account is deleted, the user can still access the administration panel (and add or delete users) and has complete access to the system.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2021-31590 affects PwnDoc’s handling of authentication tokens. A user who once had admin access could keep that access after being downgraded or deleted, including access to the administration panel. This can undermine user removal, role changes, and administrative control of the platform.

Executive priority

Treat this as high priority for any PwnDoc instance with multiple users or recent admin offboarding. The business risk is unauthorized retention of full administrative control, not remote unauthenticated compromise.

Technical view

The CVE describes incorrect JSON Web Token handling in PwnDoc versions until 0.4.0. Authorization appears to rely on token state that can remain valid after account privilege changes or deletion, allowing continued administrative actions such as adding or deleting users.

Likely exposure

Exposure is limited to organizations running affected PwnDoc versions and users who possess a valid JWT. Systems where administrators were downgraded, offboarded, or deleted are the highest concern.

Exploitation context

The source bundle does not show CISA KEV listing or active exploitation evidence. The described abuse requires a valid JWT, but impact is severe because retained admin access can persist after intended revocation.

Researcher notes

Evidence is source-limited: no CVSS, CWE, CPE, or KEV data is provided. The key validation focus is stale authorization through JWTs after privilege downgrade or account deletion, aligned to the cited PwnDoc disclosure and fix references.

Mitigation direction

  • Review PwnDoc vendor advisory, changelog, pull requests, and commits for the fixed release details.
  • Upgrade affected PwnDoc deployments outside the vulnerable version range identified by the vendor.
  • Invalidate existing sessions or JWTs after upgrade if vendor guidance supports that action.
  • Audit admin accounts and user changes made around downgrade or deletion events.
  • Restrict administrative access while remediation and account review are in progress.

Validation and detection

  • Inventory PwnDoc deployments and record their running versions.
  • Confirm whether any deployment is on a version described as affected until 0.4.0.
  • Review logs for admin actions by downgraded or deleted users.
  • Verify role changes and account deletions terminate administrative access after remediation.
  • Check vendor release notes and commits before marking the issue fixed.
Prepared
Confidence
medium
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-31590 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
8Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.