CVE-2021-40146

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 10 (High)
100% Progress
EPSS 0.79 % (82th)
0.79% Progress
Affected Products 1
Advisories 1

A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.

Weaknesses
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2021-09-11 11:15:14
(3 years ago)
Updated Date
2021-09-23 16:59:15
(3 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Any23 prior 2.5 version cpe:2.3:a:apache:any23 < 2.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...