CVE-2021-42559

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
12/01/2022
Last modified:
19/01/2022

Description

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mitre:caldera:*:*:*:*:*:*:*:* 2.8.1 (including)