CVE-2021-42559
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
12/01/2022
Last modified:
19/01/2022
Description
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mitre:caldera:*:*:*:*:*:*:*:* | 2.8.1 (including) |
To consult the complete list of CPE names with products and versions, see this page



