Lucene search

K
osvGoogleOSV:CVE-2021-40720
HistoryOct 15, 2021 - 3:15 p.m.

CVE-2021-40720

2021-10-1515:15:08
Google
osv.dev
5
ops cli
version 2.0.4
deserialization
untrusted data
arbitrary code execution
checkou_repo function
malicious file
attacker
victim machine
security vulnerability

EPSS

0.156

Percentile

96.0%

Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the checkout_repo function is called on a maliciously crafted file. An attacker can leverage this to execute arbitrary code on the victim machine.

EPSS

0.156

Percentile

96.0%