CVE-2021-23267: Improper Control of Dynamically-Managed Code Resources in Crafter Studio
Published May 16, 2022
·Updated
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods.
Affected Software
2 affected componentsFixes available
maven/org.craftercms:crafter-studio>=3.1.0<3.1.18
3.1.18
CrafterCMS Crafter Cms>=3.1<3.1.18
Event History
May 16, 2022
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionSeverityWeakness
May 17, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is CVE-2021-23267?
CVE-2021-23267 is an Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS.
2
How does CVE-2021-23267 affect Crafter Studio?
CVE-2021-23267 allows authenticated developers to execute OS commands via FreeMarker static methods in Crafter Studio.
3
What is the severity of CVE-2021-23267?
CVE-2021-23267 has a severity rating of critical with a CVSS score of 8.8.
4
How can I fix CVE-2021-23267 in Crafter Studio?
To fix CVE-2021-23267 in Crafter Studio, update to version 3.1.18 or higher.
5
Where can I find more information about CVE-2021-23267?
You can find more information about CVE-2021-23267 on the NIST website, the CrafterCMS security advisory, and the GitHub advisory.