First published: Thu Nov 11 2021(Updated: )
Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versions prior to 5.0.0.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ShardingSphere ElasticJob-UI | >=4.1.1<5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26558 is classified as a high severity vulnerability due to its potential for exploitation through deserialization of untrusted data.
To fix CVE-2021-26558, upgrade Apache ShardingSphere-UI to version 5.0.0 or later.
CVE-2021-26558 affects Apache ShardingSphere-UI versions 4.1.1 up to, but not including, 5.0.0.
CVE-2021-26558 is a deserialization of untrusted data vulnerability.
CVE-2021-26558 allows an attacker to inject outer link resources, which can lead to further compromises.