CVE Feed

    Dashboard / CVE / CVE-2021-23727

    CVE-2021-23727

    This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.

    Published:Dec 29, 2021
    Last Modified:Nov 21, 2024
    EPS:Dec 29, 2021
    EPSS Score:0.02018
    CVSS Score:7.5

    Affected Products

    Vendor
    Celeryproject
    Product
    Celery
    Vendor
    Fedoraproject
    Product
    Extra Packages For Enterprise Linux
    Vendor
    Fedoraproject
    Product
    Fedora

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High