CVE-2024-21881
Severity CVSS v4.0:
HIGH
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
12/08/2024
Last modified:
15/04/2026
Description
Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x



