EXPOSURES › CVE-2021-45807
CVE-2021-45807
CRITICAL
DETAIL
SourceNVD · cve
Published2022-01-13
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-45807 ↗
⚡ RCE
SHAME 50/100
rce
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
CVE-2021-45807 is a critical RCE vulnerability in jpress v4.2.0, confirmed by NVD and CISA KEV, indicating severe security failure.
Critical RCE vulnerability confirmed
"jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall."
Vulnerability tracked in CVE database
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
Vulnerability tracked in CISA KEV
"CISA Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
Vulnerability listed in CVE database
"CVEs and Security Vulnerabilities - OpenCVE"
Irrelevant to jpress vulnerability
"news stories faked to lure victims to scam"
Irrelevant to jpress vulnerability
"Chrome Releases"
Irrelevant to jpress vulnerability
"U.S. Judiciary Confirms Breach Of Federal Court Electronic Records System"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.