PT-2022-12122 · Lens · Lens

Published

2022-01-10

·

Updated

2022-08-09

·

CVE-2021-44458

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lens versions 5.2.6 and earlier
Description The issue allows attackers to execute arbitrary commands as the Lens user by making websocket connections from the victim's browser to Lens, enabling operation of the local terminal feature, when a malicious website is visited.
Recommendations For Lens versions 5.2.6 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2021-44458

Affected Products

Lens