← back
CVE-2021-40146

A Remote Code Execution (RCE) vulnerability exists in Apache Any23 YAMLExtractor.java

EPSS 5.5%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 5.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Sep 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →