CVE-2021-45807: Critical severity jpress Jpress vulnerability
Published Jan 13, 2022
·Updated
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin.AddonController::doUploadAndInstall.
Affected Software
1 affected component
jpress Jpress=4.2.0
Event History
Jan 13, 2022
CVE Published
via MITRE·06:22 PM
Data Sourced
via MITRE·06:22 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for jpress v4.2.0?
The vulnerability ID for jpress v4.2.0 is CVE-2021-45807.
2
What is the severity of CVE-2021-45807?
The severity of CVE-2021-45807 is critical with a CVSS score of 9.8.
3
How does the vulnerability in jpress v4.2.0 allow command execution?
The vulnerability in jpress v4.2.0 allows command execution through the io.jpress.web.admin._AddonController::doUploadAndInstall function.
4
Is there a fix available for CVE-2021-45807?
At the moment, there is no official fix available for CVE-2021-45807. It is recommended to update to a patched version once it becomes available or apply any recommended security patches.
5
Where can I find more information about jpress v4.2.0 and the vulnerability?
More information about jpress v4.2.0 and the vulnerability can be found on the JPress website (http://jpress.com) and the JPress GitHub repository (https://github.com/JPressProjects/jpress).