PT-2021-19829 · Emissary · Emissary
Pwntester
·
Published
2021-05-28
·
Updated
2022-07-02
·
CVE-2021-32647
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Emissary (affected versions not specified)
Description
The issue affects Emissary, a P2P based data-driven workflow engine, allowing post-authentication Remote Code Execution (RCE). The "CreatePlace" REST endpoint is vulnerable, accepting an
sppClassName parameter to load an arbitrary class, which can be instantiated with a specific constructor signature. An attacker may find a gadget class in the application classpath to achieve RCE, disrupt the application, crash it, or leak sensitive data.Recommendations
As a temporary workaround, consider disabling network access to Emissary from untrusted sources.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emissary