{"id":"CVE-2021-4119","aliases":["GHSA-9c5c-5j4h-8q2c"],"url":"https://o3.security/vulnerability/CVE-2021-4119","summary":"BookStack is vulnerable to Improper Access Control.","details":"bookstack is vulnerable to Improper Access Control","published":"2021-12-15T20:15:08.837Z","modified":"2026-08-07T19:48:37.107464Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"ssddanbrown/bookstack","fixedVersion":"21.11.3"}],"fix":{"url":"https://github.com/bookstackapp/bookstack/commit/e765e618547c92f4e0b46caca6fb91f0174efd99","label":"bookstackapp/bookstack@e765e61"},"references":[{"type":"FIX","url":"https://github.com/bookstackapp/bookstack/commit/e765e618547c92f4e0b46caca6fb91f0174efd99"},{"type":"FIX","url":"https://huntr.dev/bounties/135f2d7d-ab0b-4351-99b9-889efac46fca"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T19:48:37.107464Z"}}