CVE-2021-23758
Duplicate Advisory: Remote Code Execution in AjaxNetProfessional
9.8
CRITICAL
CVSS 3.1
EPSS 88.8%
描述
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-6r7c-6w96-8pvw. This link is maintained to preserve external references. ## Original Description All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
如何修補 CVE-2021-23758
要修補 CVE-2021-23758,請將受影響套件升級到下列已修補版本。
- —升級至 21.11.29.1 或更新版本
CVE-2021-23758 正在被利用嗎?
可能 — EPSS 為 88.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 21.11.29.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |