10
CVSSv2

CVE-2021-40146

Published: 11/09/2021 Updated: 23/09/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A Remote Code Execution (RCE) vulnerability exists in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache any23

Github Repositories

A PoC exploit for the Apache Any23 <=2.5 RCE vulnerability

This project is a PoC exploit for CVE-2021-40146 It will exploit an instance of Any23 &lt;=25 to perform RCE Full blog post here