Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44657

Опубликовано: 15 дек. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:stackstorm:stackstorm:*:*:*:*:*:*:*:*
Версия до 3.6.0 (исключая)

EPSS

Процентиль: 85%
0.02639
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

CVSS3: 8.8
github
около 4 лет назад

In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.

EPSS

Процентиль: 85%
0.02639
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

NVD-CWE-Other