Lucene search

K
cveMitreCVE-2021-41790
HistoryOct 21, 2021 - 9:15 a.m.

CVE-2021-41790

2021-10-2109:15:08
mitre
web.nvd.nist.gov
30
cve-2021-41790
hyland
alfresco
content services
arbitrary code execution
sandboxed environment
security vulnerability

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

47.2%

An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.

Affected configurations

Nvd
Node
alfrescoalfresco_content_servicesRange5.0.0.05.2.7.11enterprise
OR
alfrescoalfresco_content_servicesRange6.0.0.06.0.1.9enterprise
OR
alfrescoalfresco_content_servicesRange6.1.0.06.1.1.10enterprise
OR
alfrescoalfresco_content_servicesRange6.2.0.06.2.2.18enterprise
OR
alfrescoalfresco_content_servicesRange7.0.1.07.0.1.2enterprise
OR
alfrescoalfresco_content_servicesMatch7.0enterprise
OR
alfrescoalfresco_content_servicesMatch7.0.0.1enterprise
OR
alfrescoalfresco_content_servicesMatch7.0.0.2enterprise
VendorProductVersionCPE
alfrescoalfresco_content_services*cpe:2.3:a:alfresco:alfresco_content_services:*:*:*:*:enterprise:*:*:*
alfrescoalfresco_content_services7.0cpe:2.3:a:alfresco:alfresco_content_services:7.0:*:*:*:enterprise:*:*:*
alfrescoalfresco_content_services7.0.0.1cpe:2.3:a:alfresco:alfresco_content_services:7.0.0.1:*:*:*:enterprise:*:*:*
alfrescoalfresco_content_services7.0.0.2cpe:2.3:a:alfresco:alfresco_content_services:7.0.0.2:*:*:*:enterprise:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

47.2%

Related for CVE-2021-41790