Security Advisory

CVE-2021-42559

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-01-12 19:11:03
Last updated 2024-08-04 03:38:49
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.