CVE-2021-32096
07.05.2021, 04:15
The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter.
Vendor | Product | Version |
---|---|---|
nsa | emissary | 5.9.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References