Security Advisory

CVE-2021-4326

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-02-22 15:21:06
Last updated 2024-08-03 17:23:10
Assigner Zowe
State PUBLISHED

Description

A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.