Lucene search

K
cvelistMitreCVELIST:CVE-2021-32096
HistoryMay 07, 2021 - 3:51 a.m.

CVE-2021-32096

2021-05-0703:51:37
mitre
www.cve.org
3
consoleaction
csrf attack
arbitrary ruby code
console_command_string
nsa emissary 5.9.0
cve-2021-32096

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

55.8%

The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter.

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

55.8%

Related for CVELIST:CVE-2021-32096