HIGH · 7.5

CVE-2021-23727

This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. ...

Vulnerability Description

This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CeleryprojectCelery< 5.2.2
FedoraprojectExtra Packages For Enterprise Linux7.0
FedoraprojectFedora35

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-23727?

CVE-2021-23727 is a vulnerability with a CVSS score of 7.5 (HIGH). This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. ...

How severe is CVE-2021-23727?

CVE-2021-23727 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-23727?

Check the references section above for vendor advisories and patch information. Affected products include: Celeryproject Celery, Fedoraproject Extra Packages For Enterprise Linux, Fedoraproject Fedora.