Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32634

Опубликовано: 21 мая 2021
Источник: nvd
CVSS3: 7.2
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the WorkSpaceClientEnqueue.action REST endpoint. This issue may lead to post-auth Remote Code Execution. This issue has been patched in version 6.5.0. As a workaround, one can disable network access to Emissary from untrusted sources.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nsa:emissary:6.4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.03051
Низкий

7.2 High

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-502

EPSS

Процентиль: 86%
0.03051
Низкий

7.2 High

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-502