CVE-2021-23420
11.08.2021, 13:15
This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.Enginsight
Vendor | Product | Version |
---|---|---|
codeception | codeception | 𝑥 < 3.1.3 |
codeception | codeception | 4.0.0 ≤ 𝑥 < 4.1.22 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References