CVE-2021-41790: High severity hyland alfresco content services vulnerability
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41790?
CVE-2021-41790 is a vulnerability discovered in Hyland org.alfresco:alfresco-content-services through version 7.0.1.2. It allows executing scripts uploaded outside of the Data Dictionary, potentially enabling arbitrary code execution inside a sandboxed environment.
How does CVE-2021-41790 affect Alfresco Content Services?
CVE-2021-41790 affects Alfresco Content Services versions between 5.0.0.0 and 7.0.1.2, allowing an authenticated attacker to execute arbitrary code within a sandboxed environment.
What is the severity of CVE-2021-41790?
CVE-2021-41790 has a severity rating of 8.8 (high).
How can I fix CVE-2021-41790?
To fix CVE-2021-41790, it is recommended to update to a version of Alfresco Content Services that is not affected by the vulnerability (i.e., above version 7.0.1.2).
Where can I find more information about CVE-2021-41790?
You can find more information about CVE-2021-41790 in the following references: [GitHub](https://github.com/Alfresco/acs-packaging/blob/master/DISCLOSURES.md) and [The Missing Link](https://www.themissinglink.com.au/).