CVE-2021-46364: High severity magnolia content management suite vulnerability
Published Feb 11, 2022
·Updated
A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.
Affected Software
1 affected component
Magnolia-cms Magnolia Cms<6.2.4
Event History
Feb 11, 2022
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-46364?
CVE-2021-46364 has a high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2021-46364?
To fix CVE-2021-46364, upgrade to Magnolia CMS version 6.2.4 or later.
3
What versions of Magnolia CMS are affected by CVE-2021-46364?
Magnolia CMS versions 6.2.3 and below are affected by CVE-2021-46364.
4
What kind of attack is enabled by CVE-2021-46364?
CVE-2021-46364 allows attackers to execute arbitrary code via a crafted YAML file.
5
Who discovered CVE-2021-46364?
The vulnerability CVE-2021-46364 was publicly disclosed by security researchers.