CVE-2021-36202: Metasys UI
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this SSRF vulnerability?
The vulnerability ID for this SSRF vulnerability is CVE-2021-36202.
What is the severity rating of CVE-2021-36202?
The severity rating of CVE-2021-36202 is high (8.8).
How does the SSRF vulnerability in Johnson Controls Metasys work?
The SSRF vulnerability in Johnson Controls Metasys allows an authenticated attacker to inject malicious code into the MUI PDF export feature.
Which versions of Johnson Controls Metasys are affected by this vulnerability?
This vulnerability affects all 10 versions prior to 10.1.5 and all 11 versions prior to 11.0.2 of Johnson Controls Metasys.
How can I fix the SSRF vulnerability in Johnson Controls Metasys?
To fix the SSRF vulnerability, update Johnson Controls Metasys to version 10.1.5 or 11.0.2 or later.