CVE-2021-28154: Critical severity camunda bpm vulnerability
DISPUTED Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which manipulates the readFile and writeFile APIs. NOTE: the vendor states "The way we secured the app is that it does not allow any remote scripts to be opened, no unsafe scripts to be evaluated, no remote sites to be browsed."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28154?
CVE-2021-28154 is classified as a moderate severity vulnerability due to its potential for arbitrary file access.
How do I fix CVE-2021-28154?
To mitigate CVE-2021-28154, upgrade to Camunda Modeler version 4.7.0 or later.
What type of attack does CVE-2021-28154 allow?
CVE-2021-28154 allows a remote attacker to exploit the vulnerable ipcRenderer IPC interface to manipulate file read and write operations.
Is CVE-2021-28154 applicable to all versions of Camunda Modeler?
CVE-2021-28154 affects all versions of Camunda Modeler up to and including 4.6.0.
What are the consequences of exploiting CVE-2021-28154?
Exploiting CVE-2021-28154 could lead to unauthorized access to sensitive files and data manipulation.