First published: Tue Dec 07 2021(Updated: )
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Avalanche | <6.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42127 is a deserialization of untrusted data vulnerability that exists in Ivanti Avalanche before version 6.3.3.
CVE-2021-42127 allows arbitrary code execution via the Data Repository Service in Ivanti Avalanche before version 6.3.3.
CVE-2021-42127 has a severity rating of critical with a CVSS score of 9.8.
To fix CVE-2021-42127, it is recommended to upgrade to version 6.3.3 of Ivanti Avalanche.
You can find more information about CVE-2021-42127 in the Ivanti Avalanche 6.3.3 Security Alert article: https://forums.ivanti.com/s/article/Security-Alert-CVE-s-Addressed-in-Avalanche-6-3-3