Vulnerability Description
An issue was discovered in CubeCoders AMP before 2.1.1.8. A lack of validation of the Java Version setting means that an unintended executable path can be set. The result is that high-privileged users can trigger code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cubecoders | Amp | < 2.1.1.8 |
Related Weaknesses (CWE)
References
- https://github.com/CubeCoders/AMP/issues/464Third Party Advisory
- https://github.com/CubeCoders/AMP/issues/464Third Party Advisory
FAQ
What is CVE-2021-34539?
CVE-2021-34539 is a vulnerability with a CVSS score of 7.2 (HIGH). An issue was discovered in CubeCoders AMP before 2.1.1.8. A lack of validation of the Java Version setting means that an unintended executable path can be set. The result is that high-privileged users...
How severe is CVE-2021-34539?
CVE-2021-34539 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-34539?
Check the references section above for vendor advisories and patch information. Affected products include: Cubecoders Amp.