Vulnerability record · CVE-2021-41171 · published 22 October 2021
CVE-2021-41171: Elabftw improper restriction of authentication attempts vulnerability
Elabftw · Elabftw
eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a brute-force protection mechanism by using many different forged PHPSESSID values in HTTP Cookie header. This issue has been addressed by implementing brute force login protection, as recommended by Owasp with Device Cookies. This mechanism will not impact users and will effectively thwart any brute-force attempts at guessing passwords. The only correct way to address this is to upgrade to version 4.1.0. Adding rate limitation upstream of the eLabFTW service is of course a valid option, with or without upgrading.
Description
eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a brute-force protection mechanism by using many different forged PHPSESSID values in HTTP Cookie header. This issue has been addressed by implementing brute force login protection, as recommended by Owasp with Device Cookies. This mechanism will not impact users and will effectively thwart any brute-force attempts at guessing passwords. The only correct way to address this is to upgrade to version 4.1.0. Adding rate limitation upstream of the eLabFTW service is of course a valid option, with or without upgrading.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/elabftw/elabftw/commit/8e92afeec4c3a68dc88333881b7e6307f425706b | PatchThird Party Advisory |
| https://github.com/elabftw/elabftw/releases/tag/4.1.0 | Release NotesThird Party Advisory |
| https://github.com/elabftw/elabftw/security/advisories/GHSA-q67h-5pc3-g6jv | Third Party Advisory |
| https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies | Third Party Advisory |
| https://www.exploit-db.com/docs/50436 | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/elabftw/elabftw/commit/8e92afeec4c3a68dc88333881b7e6307f425706b | PatchThird Party Advisory |
| https://github.com/elabftw/elabftw/releases/tag/4.1.0 | Release NotesThird Party Advisory |
| https://github.com/elabftw/elabftw/security/advisories/GHSA-q67h-5pc3-g6jv | Third Party Advisory |
| https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies | Third Party Advisory |
| https://www.exploit-db.com/docs/50436 | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2021-41171 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41171), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.