CVE-2021-32634: Deserialization of Untrusted Data in Emissary
Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the WorkSpaceClientEnqueue.action REST endpoint. This issue may lead to post-auth Remote Code Execution. This issue has been patched in version 6.5.0. As a workaround, one can disable network access to Emissary from untrusted sources.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32634?
CVE-2021-32634 is classified as a medium severity vulnerability due to its potential to lead to remote code execution.
How do I fix CVE-2021-32634?
To fix CVE-2021-32634, upgrade Emissary to version 6.4.1 or later, where the vulnerability is addressed.
What types of attacks can CVE-2021-32634 facilitate?
CVE-2021-32634 can facilitate unsafe deserialization attacks, allowing an attacker to execute arbitrary code after authentication.
Is CVE-2021-32634 present in earlier versions of Emissary?
Yes, CVE-2021-32634 affects Emissary version 6.4.0 and is not present in later versions.
What components of Emissary are affected by CVE-2021-32634?
CVE-2021-32634 specifically affects the WorkSpaceClientEnqueue.action component in Emissary.