An attacker with low privileges can exploit the weakness in internally used text extraction reports (Translation Tools) which will enable the execution of arbitrary commands in the background. An attacker could thereby control the behavior of the application compromising all its data.
Code Injection, Command Injection, OS command injection, CVE-2021-44231
Reason and Prerequisites
Internally used reports were released by accident.
- Coding is deactivated (commented out).
- Please apply/implement this note.
- There is no impact on existing functionality.
Available fix and Supported packages
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.