You are viewing a plain text version of this content. The canonical link for it is here.
Posted to announce@apache.org by Lewis John McGibbney <le...@apache.org> on 2021/09/11 00:03:59 UTC
CVE-2021-40146: A Remote Code Execution (RCE) vulnerability exists in Apache Any23 YAMLExtractor.java
Description:
A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.
Credit:
The Apache Any23 Project Management Committee would like to thank Zhuxuan Wu for reporting the security vulnerability.
Fix and Action:
Upgrade immediately to Any23 2.5 see https://any23.apache.org/download.html
Support
Please find us on the Any23 community mailing lists at https://any23.apache.org/mailing-lists.html
Sincerely
lewismc
(On behalf of the Any23 PMC)