CVE-2021-31581
Summary
| CVE | CVE-2021-31581 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-22 19:15:00 UTC |
| Updated | 2021-08-04 01:57:00 UTC |
| Description | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later). |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Akkadianlabs | Ova Appliance | All | All | All | All |
| Application | Akkadianlabs | Provisioning Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Akkadian Provisioning Manager Multiple Vulnerabilities Disclosure | Rapid7 Blog | MISC | www.rapid7.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Cale Black, Ryan Villarreal, and Jonathan Peterson of Rapid7
Legacy QID Mappings
- 730114 Akkadian Provisioning Manager Multiple Vulnerabilities