PT-2021-19829 · Emissary · Emissary

Pwntester

·

Published

2021-05-28

·

Updated

2022-07-02

·

CVE-2021-32647

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emissary (affected versions not specified)
Description The issue affects Emissary, a P2P based data-driven workflow engine, allowing post-authentication Remote Code Execution (RCE). The "CreatePlace" REST endpoint is vulnerable, accepting an sppClassName parameter to load an arbitrary class, which can be instantiated with a specific constructor signature. An attacker may find a gadget class in the application classpath to achieve RCE, disrupt the application, crash it, or leak sensitive data.
Recommendations As a temporary workaround, consider disabling network access to Emissary from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32647
GHSA-PH73-7V9R-WG32

Affected Products

Emissary