← Back

CVE-2021-42559

nvd nist
Published: Jan 12, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.

Affected (1)

Products: Mitre: Caldera
1 product
Caldera
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.8.1

Timeline

No history available yet.