PT-2021-4860 · Unknown · Cron-Utils

Niels

+1

·

Published

2021-10-29

·

Updated

2021-11-19

·

CVE-2021-41269

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cron-utils versions up to 9.1.2
Description A template injection issue was identified in cron-utils, enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE). This issue affects projects using the @Cron annotation to validate untrusted Cron expressions.
Recommendations For versions up to 9.1.2, please upgrade to version 9.1.6 to resolve the issue. As a temporary workaround, consider avoiding the use of the @Cron annotation to validate untrusted Cron expressions until the patch is applied. There are no known workarounds other than upgrading to the patched version.

Exploit

Fix

Code Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05588
BDU:2021-05647
CVE-2021-41269
GHSA-P9M8-27X8-RG87

Affected Products

Cron-Utils