CVE-2021-40146
A Remote Code Execution (RCE) vulnerability exists in Apache Any23 YAMLExtractor.java
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 5.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
11 sep 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.
Productos afectados
Apache Software Foundation · Apache Any23¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →