← Back

CVE-2021-3396

nvd nist
Published: Feb 17, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.

Affected (7)

3 products
Horizon
Meridian
Newts
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
From 16.0.0 to 27.0.3
Opennms
From 2016.1.0 to 2016.1.24
From 2017.1.0 to 2017.1.26
From 2018.1.0 to 2018.1.25
From 2019.1.0 to 2019.1.16
From 2020.1.0 to 2020.1.5
Before 1.5.3

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.