CVE-2011-4356: Medium severity celery vulnerability
Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid and --gid arguments to celerybeat, celeryddetach, celeryd-multi, and celeryev, which allows local users to gain privileges via vectors involving crafted code that is executed by the worker process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4356?
CVE-2011-4356 is considered to have a high severity due to the potential for local privilege escalation.
How do I fix CVE-2011-4356?
To fix CVE-2011-4356, upgrade Celery to version 2.4.4, 2.3.4, or 2.2.8.
Which versions of Celery are affected by CVE-2011-4356?
CVE-2011-4356 affects Celery versions 2.1.0 through 2.4.3.
What type of vulnerability is CVE-2011-4356?
CVE-2011-4356 is a local privilege escalation vulnerability that can be exploited by local users.
Are there any workarounds for CVE-2011-4356?
No specific workarounds are recommended for CVE-2011-4356, so updating to the fixed versions is essential.