CVE-2021-46361
CRITICALCVSS 9.8/10EPSS 2.61%
Last modified
CVE-2021-46361 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.. EPSS estimates a 2.61% chance of exploitation in the next 30 days.
Description
An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Magnolia-Cms | Magnolia Cms | < 6.2.12 |
References
- https://docs.magnolia-cms.com/product-docs/6.2/Releases/Release-notes-for-Magnolia-CMS-6.2.12.html#_security_advisoryRelease Notes, Vendor Advisory
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2021-46361-FreeMarker%20Bypass-Magnolia%20CMSExploit, Third Party Advisory
- https://docs.magnolia-cms.com/product-docs/6.2/Releases/Release-notes-for-Magnolia-CMS-6.2.12.html#_security_advisoryRelease Notes, Vendor Advisory
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2021-46361-FreeMarker%20Bypass-Magnolia%20CMSExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-46361?
An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.
How severe is CVE-2021-46361?
CVE-2021-46361 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 2.61% probability of exploitation in the next 30 days.
How do I fix CVE-2021-46361?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-46351There is an Assertion 'local_tza == ecma_date_local_time_zon…5.5
- CVE-2021-46353An information disclosure in web interface in D-Link DIR-X18…5.3
- CVE-2021-46354Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed …7.5
- CVE-2021-46355OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS…5.4
- CVE-2021-46359FISCO-BCOS release-3.0.0-rc2 contains a denial of service vu…7.5
- CVE-2021-46360Authenticated remote code execution (RCE) in Composr-CMS 10.…8.8
- CVE-2021-46362A Server-Side Template Injection (SSTI) vulnerability in the…9.8
- CVE-2021-46363An issue in the Export function of Magnolia v6.2.3 and below…7.8
- CVE-2021-46364A vulnerability in the Snake YAML parser of Magnolia CMS v6.…7.8
- CVE-2021-46365An issue in the Export function of Magnolia v6.2.3 and below…7.8
- CVE-2021-46366An issue in the Login page of Magnolia CMS v6.2.3 and below …8.8
- CVE-2021-46367RiteCMS version 3.1.0 and below suffers from a remote code e…7.2
Are you affected by CVE-2021-46361?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
