CVE-2021-32639: Server-Side Request Forgery (SSRF) in emissary:emissary
Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the RegisterPeerAction endpoint and the AddChildDirectoryAction endpoint are vulnerable to SSRF. This vulnerability may lead to credential leaks. Emissary version 7.0 contains a patch. As a workaround, disable network access to Emissary from untrusted sources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32639?
CVE-2021-32639 is categorized as a high-severity Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2021-32639?
To mitigate CVE-2021-32639, upgrade Emissary to a version later than 6.4.0.
What impact does CVE-2021-32639 have on my system?
CVE-2021-32639 may lead to credential exposure and other security risks via SSRF.
Which endpoints are affected by CVE-2021-32639?
The vulnerable endpoints in CVE-2021-32639 are RegisterPeerAction and AddChildDirectoryAction.
Is my version of Emissary vulnerable to CVE-2021-32639?
Emissary version 6.4.0 and earlier are vulnerable to CVE-2021-32639.