PT-2021-4860 · Unknown · Cron-Utils
Niels
+1
·
Published
2021-10-29
·
Updated
2021-11-19
·
CVE-2021-41269
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cron-utils versions up to 9.1.2
Description
A template injection issue was identified in cron-utils, enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE). This issue affects projects using the
@Cron annotation to validate untrusted Cron expressions.Recommendations
For versions up to 9.1.2, please upgrade to version 9.1.6 to resolve the issue. As a temporary workaround, consider avoiding the use of the
@Cron annotation to validate untrusted Cron expressions until the patch is applied. There are no known workarounds other than upgrading to the patched version.Exploit
Fix
Code Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cron-Utils