Security Advisory

CVE-2021-42561

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-01-12 18:52:40
Last updated 2024-08-04 03:38:49
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell commands.