9

CVE-2021-44657

Exploit
In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
StackstormStackstorm Version < 3.6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.47% 0.824
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/StackStorm/st2/pull/5359
Patch
Third Party Advisory
https://github.com/pallets/jinja/issues/549
Third Party Advisory
Exploit
Issue Tracking
https://podalirius.net/en/articles/python-vulnerabilities-code-execution-in-jinja-templates/
Third Party Advisory
Exploit
https://stackstorm.com/2021/12/16/stackstorm-v3-6-0-released/
Vendor Advisory
Release Notes