6.9

CVE-2011-4356

Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid and --gid arguments to celerybeat, celeryd_detach, celeryd-multi, and celeryev, which allows local users to gain privileges via vectors involving crafted code that is executed by the worker process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Celeryproject ≫ Celery Version 2.1.0
Celeryproject ≫ Celery Version 2.2.0
Celeryproject ≫ Celery Version 2.2.1
Celeryproject ≫ Celery Version 2.2.2
Celeryproject ≫ Celery Version 2.2.3
Celeryproject ≫ Celery Version 2.2.4
Celeryproject ≫ Celery Version 2.2.5
Celeryproject ≫ Celery Version 2.2.6
Celeryproject ≫ Celery Version 2.2.7
Celeryproject ≫ Celery Version 2.3.0
Celeryproject ≫ Celery Version 2.3.1
Celeryproject ≫ Celery Version 2.3.2
Celeryproject ≫ Celery Version 2.3.3
Celeryproject ≫ Celery Version 2.4.0
Celeryproject ≫ Celery Version 2.4.1
Celeryproject ≫ Celery Version 2.4.2
Celeryproject ≫ Celery Version 2.4.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.255
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/46973
http://www.securityfocus.com/bid/50825
https://github.com/ask/celery/blob/master/docs/sec/CELERYSA-0001.txt
Patch
https://github.com/ask/celery/pull/544