Record summary

CVE-2021-43496 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHClustering Local File InclusionCVSS 7.5

Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.

Impact

This vulnerability can result in unauthorized access to sensitive files and directories, as well as the execution of arbitrary code on the affected system.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-22
AuthorsEvan Rubinstein
Template tagscve2021cvelficlusteringclustering_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:clustering_project:clustering:2019-07-26:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2