Lucene search

K
osvGoogleOSV:CVE-2021-39181
HistorySep 01, 2021 - 8:15 p.m.

CVE-2021-39181

2021-09-0120:15:00
Google
osv.dev
4
openolat
lms
java class loading
vulnerability
user account
authoring role
arbitrary code
attack
upgrade

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

58.4%

OpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a course) any class on the Java classpath can be instantiated, including spring AOP bean factories. This can be used to execute code arbitrary code by the attacker. The attack requires an OpenOlat user account with the authoring role. It can not be exploited by unregistered users. The problem is fixed in versions 15.3.18, 15.5.3, and 16.0.0. There are no known workarounds aside from upgrading.

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

58.4%

Related for OSV:CVE-2021-39181