6.8
CVSSv2

CVE-2021-46364

Published: 11/02/2022 Updated: 29/03/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows malicious users to execute arbitrary code via a crafted YAML file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

magnolia-cms magnolia cms

Github Repositories

CVE-2021-46364: YAML Deserialization in Magnolia CMS

CVE-2021-46364: YAML Deserialization in Magnolia CMS Magnolia (versions <=623) has a Snake YAML parser which is vulnerable to deserialization attacks that can allow an attacker to call arbitrary Java constructors when importing YAML files Remote Code Execution has been achieved using this vulnerability Vendor Disclosure: The vendor's disclosure and fix for this