Skip to content
COOEY

EXPOSURES › CVE-2021-45807

CVE-2021-45807

CRITICAL
DETAIL
SourceNVD · cve Published2022-01-13 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-45807 ↗
⚡ RCE SHAME 50/100 rce

jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
CVE-2021-45807 is a critical RCE vulnerability in jpress v4.2.0, confirmed by NVD and CISA KEV, indicating severe security failure.
cooey ↗ severe-fallout -0.90
Critical RCE vulnerability confirmed
"jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall."
www.cvefind.com ↗ severe-fallout -0.50
Vulnerability tracked in CVE database
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
cvefeed.io ↗ severe-fallout -0.50
Vulnerability tracked in CISA KEV
"CISA Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
app.opencve.io ↗ severe-fallout -0.50
Vulnerability listed in CVE database
"CVEs and Security Vulnerabilities - OpenCVE"
www.theguardian.com ↗ severe-fallout +0.00
Irrelevant to jpress vulnerability
"news stories faked to lure victims to scam"
chromereleases.googleblog.com ↗ severe-fallout +0.00
Irrelevant to jpress vulnerability
"Chrome Releases"
dailysecurityreview.com ↗ severe-fallout +0.00
Irrelevant to jpress vulnerability
"U.S. Judiciary Confirms Breach Of Federal Court Electronic Records System"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.