CVE-2021-41238 is a critical authorization bypass vulnerability affecting Hangfire.Core versions 1.7.25 and earlier. This flaw allows remote, unauthorized access to the Hangfire Dashboard UI, which could expose sensitive background job data. The vulnerability stems from a change that removed the default "local requests only" authorization filter, impacting installations using the default DashboardOptions.Authorization property. Rated 7.5 HIGH on the CVSS scale (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to full disclosure of sensitive information. There are no authentication requirements or user interaction needed for a successful attack. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) has been identified. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.25CPE matchmatch criteria | cpe:2.3:a:hangfire:hangfire:1.7.25:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.