Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-33191

Опубликовано: 24 авг. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through a "c2-update" command. Said command is then executed using the same privileges as the application binary. This was addressed in version 0.10.0

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:nifi_minifi_c\+\+:*:*:*:*:*:*:*:*
Версия от 0.5.0 (включая) до 0.10.0 (исключая)

EPSS

Процентиль: 89%
0.04422
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-78
CWE-78

Связанные уязвимости

github
больше 3 лет назад

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through a "c2-update" command. Said command is then executed using the same privileges as the application binary. This was addressed in version 0.10.0

EPSS

Процентиль: 89%
0.04422
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-78
CWE-78