PT-2024-18964 · Unknown · Code Agent
Snyk
·
Published
2024-12-06
·
Updated
2024-12-06
·
CVE-2024-21571
CVSS v3.1
8.1
High
| Vector | AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Code Agent versions all
Description
A remote code execution vulnerability has been identified, enabling an attacker to execute arbitrary code within the Code Agent container. Exploiting this issue requires an attacker to have network access to the Code Agent within the deployment environment. External exploitation is unlikely and depends on cluster misconfigurations and/or chaining with another vulnerability. However, internal exploitation could still be possible with a cluster misconfiguration.
Recommendations
For all versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Code Agent