PT-2021-19909 · Manageiq · Manageiq

Gregg Tanzillo

+1

·

Published

2021-07-21

·

Updated

2025-07-29

·

CVE-2021-32756

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ManageIQ versions prior to jansa-4 ManageIQ versions prior to kasparov-2 ManageIQ versions prior to lasker-1
Description The issue is related to a flaw in the MiqExpression module where a low privilege user could enter a crafted Ruby string that would be evaluated, allowing an attacker to execute arbitrary code with root privileges on the host system.
Recommendations For versions prior to jansa-4, update to jansa-4 or later. For versions prior to kasparov-2, update to kasparov-2 or later. For versions prior to lasker-1, update to lasker-1 or later. As a temporary workaround, consider restricting users, via RBAC, to only the part of the application that they need access to, to limit the surface of the attack.

Fix

Code Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2021-32756
GHSA-32X4-VJ4R-57RQ

Affected Products

Manageiq