First published: Tue Dec 03 2019(Updated: )
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Zanata | >=3.0.0<=3.1.2 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4486 is a vulnerability in Zanata 3.0.0 through 3.1.2 that allows remote code execution (RCE) due to EL interpolation in logging.
CVE-2013-4486 is classified as critical, with a severity score of 9.8.
CVE-2013-4486 affects Redhat Zanata versions 3.0.0 through 3.1.2.
To fix CVE-2013-4486, update your Zanata installation to a version that is not affected by the vulnerability.
You can find more information about CVE-2013-4486 in the following references: [link1](https://access.redhat.com/security/cve/cve-2013-4486), [link2](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4486), [link3](https://github.com/zanata/zanata-server/wiki/Security-advisories).