CVE-2021-32096

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
07/05/2021
Last modified:
19/05/2021

Description

The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nsa:emissary:5.9.0:*:*:*:*:*:*:*