CVE-2021-32834: GHSL-2021-063: Arbitrary code execution in Eclipse Keti - CVE-2021-32834
Published Aug 30, 2021
·Updated
A user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox.
Affected Software
1 affected component
Eclipse Keti
Event History
Aug 30, 2021
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Sep 9, 2021
CVE Published
via MITRE·01:50 AM
Data Sourced
via MITRE·01:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-32834?
CVE-2021-32834 is a vulnerability in Eclipse Keti that allows a user to run arbitrary code by sending malicious Groovy scripts.
2
How does CVE-2021-32834 affect Eclipse Keti?
CVE-2021-32834 affects Eclipse Keti by allowing a user to escape the configured Groovy sandbox and run arbitrary code.
3
How severe is CVE-2021-32834?
CVE-2021-32834 has a severity rating of critical with a value of 9.9.
4
What is Attribute Based Access Control (ABAC)?
Attribute Based Access Control (ABAC) is a security model that determines access to resources based on attributes assigned to users and resources.
5
How can I fix CVE-2021-32834?
To fix CVE-2021-32834, update Eclipse Keti to a version that includes a patch for the vulnerability.