ZDI-21-1329: Commvault CommCell DataProvider JavaScript Sandbox Escape Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DataProvider class. The issue results from the lack of proper validation of a user-supplied string before executing it as JavaScript code. An attacker can leverage this vulnerability to escape the JavaScript sandbox and execute Java code in the context of NETWORK SERVICE.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-21-1329?
The severity of ZDI-21-1329 is high due to the potential for remote code execution.
How do I fix ZDI-21-1329?
To fix ZDI-21-1329, update your Commvault CommCell software to the latest patched version.
Who is affected by ZDI-21-1329?
All installations of Commvault CommCell that haven't been updated are affected by ZDI-21-1329.
Can ZDI-21-1329 be exploited without authentication?
No, while ZDI-21-1329 requires authentication, the vulnerability allows the authentication mechanism to be bypassed.
What kind of attack does ZDI-21-1329 facilitate?
ZDI-21-1329 allows remote attackers to execute arbitrary code on the affected systems.