CVE Vulnerabilities

CVE-2021-4326

Published: Mar 01, 2023 | Modified: Aug 08, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.

Affected Software

Name Vendor Start Version End Version
Zowe Linuxfoundation 1.16.0 (including) 1.28.2 (excluding)
Zowe Linuxfoundation 2.0.0 (including) 2.5.0 (excluding)

References