Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-28154

Опубликовано: 11 мар. 2021
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which manipulates the readFile and writeFile APIs. NOTE: the vendor states "The way we secured the app is that it does not allow any remote scripts to be opened, no unsafe scripts to be evaluated, no remote sites to be browsed.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:camunda:modeler:*:*:*:*:*:*:*:*
Версия до 4.6.0 (включая)

EPSS

Процентиль: 57%
0.00351
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.1
github
больше 3 лет назад

** DISPUTED ** Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which manipulates the readFile and writeFile APIs. NOTE: the vendor states "The way we secured the app is that it does not allow any remote scripts to be opened, no unsafe scripts to be evaluated, no remote sites to be browsed."

EPSS

Процентиль: 57%
0.00351
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-862