CVE-2021-23258
Summary
| CVE | CVE-2021-23258 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-02 16:15:00 UTC |
| Updated | 2021-12-03 18:17:00 UTC |
| Description | Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE). |
Risk And Classification
Problem Types: CWE-913
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Craftercms | Crafter Cms | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisories — Crafter CMS 3.1.14 documentation | MISC | docs.craftercms.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Kai Zhao (ToTU Security Team)
There are currently no legacy QID mappings associated with this CVE.