Vulnerability Description
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Etherpad | Etherpad | 1.8.13 |
Related Weaknesses (CWE)
References
- https://blog.sonarsource.com/etherpad-code-execution-vulnerabilitiesExploitThird Party Advisory
- https://github.com/ether/etherpad-lite/releasesRelease NotesThird Party Advisory
- https://blog.sonarsource.com/etherpad-code-execution-vulnerabilitiesExploitThird Party Advisory
- https://github.com/ether/etherpad-lite/releasesRelease NotesThird Party Advisory
FAQ
What is CVE-2021-34816?
CVE-2021-34816 is a vulnerability with a CVSS score of 7.2 (HIGH). An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.
How severe is CVE-2021-34816?
CVE-2021-34816 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-34816?
Check the references section above for vendor advisories and patch information. Affected products include: Etherpad Etherpad.