CVE-2021-42094: Command Injection
Published Oct 7, 2021
·Updated
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
Affected Software
1 affected component
Zammad Zammad<4.1.1
Event History
Oct 7, 2021
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-42094?
The severity of CVE-2021-42094 is critical with a CVSS score of 9.8.
2
How can a command injection occur in Zammad before version 4.1.1?
A command injection can occur in Zammad before version 4.1.1 via custom Packages.
3
What software is affected by CVE-2021-42094?
The affected software is Zammad before version 4.1.1.
4
How do I fix CVE-2021-42094?
To fix CVE-2021-42094, it is recommended to update Zammad to version 4.1.1 or later.
5
Is there any additional information available for CVE-2021-42094?
Yes, you can find more information about CVE-2021-42094 in the advisory at https://zammad.com/en/advisories/zaa-2021-18.