CVE-2021-42559

HIGH

Mitre Caldera < 2.8.1 - Command Injection

Title source: rule
STIX 2.1

Description

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.

Exploits (1)

nomisec WRITEUP
by mbadanoiu · poc
https://github.com/mbadanoiu/CVE-2021-42559

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0401
EPSS Percentile 88.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
mitre/caldera < 2.8.1
Published Jan 12, 2022
Tracked Since Feb 18, 2026