You are viewing a plain text version of this content. The canonical link for it is here.
Posted to announce@apache.org by Lewis John McGibbney <le...@apache.org> on 2021/09/11 00:03:59 UTC

CVE-2021-40146: A Remote Code Execution (RCE) vulnerability exists in Apache Any23 YAMLExtractor.java

Description:

A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.

Credit:

The Apache Any23 Project Management Committee would like to thank Zhuxuan Wu for reporting the security vulnerability.

Fix and Action:

Upgrade immediately to Any23 2.5 see https://any23.apache.org/download.html

Support

Please find us on the Any23 community mailing lists at https://any23.apache.org/mailing-lists.html

Sincerely
lewismc
(On behalf of the Any23 PMC)