CVE-2021-23727
Last modified
CVE-2021-23727 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). EPSS estimates a 3.88% chance of exploitation in the next 30 days.
Description
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Celeryproject | Celery | < 5.2.2 |
| Fedoraproject | Extra Packages For Enterprise Linux | 7.0 |
| Fedoraproject | Fedora | 35 |
References
- https://github.com/celery/celery/blob/master/Changelog.rst%23522Broken Link, Release Notes, Third Party Advisory
- https://snyk.io/vuln/SNYK-PYTHON-CELERY-2314953Exploit, Third Party Advisory
- https://github.com/celery/celery/blob/master/Changelog.rst%23522Broken Link, Release Notes, Third Party Advisory
- https://snyk.io/vuln/SNYK-PYTHON-CELERY-2314953Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-23727?
How severe is CVE-2021-23727?
How do I fix CVE-2021-23727?
Are you affected by CVE-2021-23727?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
