Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-23727

Опубликовано: 29 дек. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6
CVSS3: 7.5

Описание

This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

5.3.6-1
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

not-affected

5.2.3-1
esm-apps/noble

needs-triage

esm-apps/resolute

not-affected

5.3.6-1
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

needs-triage

Показывать по

EPSS

Процентиль: 89%
0.03877
Низкий

6 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8
redhat
больше 4 лет назад

This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.

CVSS3: 7.5
nvd
больше 4 лет назад

This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.

CVSS3: 7.5
debian
больше 4 лет назад

This affects the package celery before 5.2.2. It by default trusts the ...

CVSS3: 7.5
github
больше 4 лет назад

OS Command Injection in celery

EPSS

Процентиль: 89%
0.03877
Низкий

6 Medium

CVSS2

7.5 High

CVSS3