Vulnerabilities > CVE-2021-4326 - Unspecified vulnerability in Linuxfoundation Zowe 1.16.0/2.0.0

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
linuxfoundation

Summary

A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.

Vulnerable Configurations

Part Description Count
Application
Linuxfoundation
2