Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32647

Опубликовано: 01 июн. 2021
Источник: nvd
CVSS3: 8
CVSS3: 9.1
CVSS2: 6.5
EPSS Низкий

Описание

Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication Remote Code Execution (RCE). The CreatePlace REST endpoint accepts an sppClassName parameter which is used to load an arbitrary class. This class is later instantiated using a constructor with the following signature: <constructor>(String, String, String). An attacker may find a gadget (class) in the application classpath that could be used to achieve Remote Code Execution (RCE) or disrupt the application. Even though the chances to find a gadget (class) that allow arbitrary code execution are low, an attacker can still find gadgets that could potentially crash the application or leak sensitive data. As a work around disable network access to Emissary from untrusted sources.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nsa:emissary:6.4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03428
Низкий

8 High

CVSS3

9.1 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-74
CWE-470

EPSS

Процентиль: 87%
0.03428
Низкий

8 High

CVSS3

9.1 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-74
CWE-470