PT-2021-19909 · Manageiq · Manageiq
Gregg Tanzillo
+1
·
Published
2021-07-21
·
Updated
2025-07-29
·
CVE-2021-32756
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ManageIQ versions prior to jansa-4
ManageIQ versions prior to kasparov-2
ManageIQ versions prior to lasker-1
Description
The issue is related to a flaw in the MiqExpression module where a low privilege user could enter a crafted Ruby string that would be evaluated, allowing an attacker to execute arbitrary code with root privileges on the host system.
Recommendations
For versions prior to jansa-4, update to jansa-4 or later.
For versions prior to kasparov-2, update to kasparov-2 or later.
For versions prior to lasker-1, update to lasker-1 or later.
As a temporary workaround, consider restricting users, via RBAC, to only the part of the application that they need access to, to limit the surface of the attack.
Fix
Code Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Manageiq