CVE-2021-44458

HIGH

Mirantis Lens < 5.2.6 - Authentication Bypass

Title source: rule

Description

Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal feature. This would allow the attacker to execute arbitrary commands as the Lens user.

Scores

CVSS v3 8.3
EPSS 0.0014
EPSS Percentile 33.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Classification

CWE
CWE-287 CWE-346
Status published

Affected Products (1)

mirantis/lens < 5.2.6

Timeline

Published Jan 10, 2022
Tracked Since Feb 18, 2026