CVE-2021-32305: OS Command Injection
Published May 18, 2021
·Updated
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
Affected Software
1 affected component
WebSVN WebSVN<2.6.1
Remediation
Patch Available
Event History
May 18, 2021
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-32305.
2
What is the severity of CVE-2021-32305?
The severity of CVE-2021-32305 is critical with a CVSS score of 9.8.
3
What is the description of CVE-2021-32305?
CVE-2021-32305 is a vulnerability in WebSVN before 2.6.1 that allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
4
What software is affected by CVE-2021-32305?
WebSVN versions up to and excluding 2.6.1 are affected by CVE-2021-32305.
5
Is there a fix available for CVE-2021-32305?
Yes, updating WebSVN to version 2.6.1 or later will fix the vulnerability.