Lucene search

K
osvGoogleOSV:CVE-2021-32096
HistoryMay 07, 2021 - 4:15 a.m.

CVE-2021-32096

2021-05-0704:15:07
Google
osv.dev
5
nsa
emissary
csrf
ruby code
injection
security vulnerability
console_command_string

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

55.8%

The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter.

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

55.8%

Related for OSV:CVE-2021-32096