Cyber Resilience

CVE-2021-41974

Critical

Published: 08 October 2021

Published
08 October 2021
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score 0.0023 45.6th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2021-41974 is a critical-severity Improper Authorization (CWE-285) vulnerability in Tad Book3 Project Tad Book3. Its CVSS base score is 9.1 (Critical).

Operationally, ranked at the 45.6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

tad book3 project
tad book3
≤ 3.9

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-306 CWE-285

Requiring identification and rationale for actions allowed without authentication ensures critical functions are not left unprotected by forcing review of authentication requirements.

addresses: CWE-285 CWE-306

Mandating explicit authorization of mobile device connections reduces the risk of improper authorization decisions for system access.

addresses: CWE-285 CWE-306

Ensures authorization decisions are always performed by a complete and analyzable reference monitor.

addresses: CWE-285 CWE-306

Auditing session actions allows identification of improper authorization decisions and enforcement failures.

addresses: CWE-285 CWE-306

The process verifies authorization mechanisms function as intended before system approval.

addresses: CWE-285 CWE-306

By limiting enabled features to only those needed, the control strengthens authorization by removing opportunities for unauthorized use of excess functionality.

addresses: CWE-285 CWE-306

Dedicated authorization servers support policy-based decisions, mitigating improper authorization.

addresses: CWE-285 CWE-306

Protecting the shutoff from unauthorized activation enforces proper authorization for this critical operation.

References