CVE-2021-23259: Groovy Sandbox Bypass
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23259?
CVE-2021-23259 is a vulnerability in Crafter CMS that allows authenticated users with Administrator or Developer roles to execute arbitrary OS commands through a Groovy Script.
How can an attacker exploit CVE-2021-23259?
Attackers can exploit CVE-2021-23259 by using a Groovy Script in Crafter CMS to execute arbitrary OS commands remotely.
What is the severity of CVE-2021-23259?
CVE-2021-23259 has a severity rating of 7.2 (High).
Which versions of Crafter CMS are affected by CVE-2021-23259?
Crafter CMS versions between 3.1.0 and 3.1.12 are affected by CVE-2021-23259.
How can I fix CVE-2021-23259?
To fix CVE-2021-23259, update your Crafter CMS installation to a version higher than 3.1.12.