Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-47935

Опубликовано: 10 мая 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with base64-encoded compressed pickle payloads in the data field to achieve code execution with application privileges.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sentry:sentry:8.2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00927
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
github
4 месяца назад

Sentry: Superusers can execute arbitrary commands by injecting malicious pickle-serialized objects through audit log entry data parameter

EPSS

Процентиль: 58%
0.00927
Низкий

8.8 High

CVSS3

Дефекты

CWE-94