GHSL-2021-076: Arbitrary command execution in Gerapy - CVE-2021-32849
Published Nov 24, 2021
·Updated
An authenticated attacker can execute arbitrary commands on the system.
Affected Software
1 affected component
Gerapy Gerapy
Event History
Nov 24, 2021
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2021-076?
The severity of GHSL-2021-076 is rated as 69.
2
How do I fix GHSL-2021-076?
To fix GHSL-2021-076, ensure you update Gerapy to the patched version that addresses the arbitrary command execution vulnerability.
3
Who is affected by GHSL-2021-076?
GHSL-2021-076 affects users of Gerapy who have not implemented the necessary security measures against authenticated attackers.
4
What kind of attacks can be performed using GHSL-2021-076?
An attacker exploiting GHSL-2021-076 can execute arbitrary commands on the system, potentially leading to full system compromise.
5
Is authentication required to exploit GHSL-2021-076?
Yes, GHSL-2021-076 requires authentication, allowing only authenticated attackers to exploit the vulnerability.