Vulnerabilities > Mirantis > Lens > 4.1.0

DATE CVE VULNERABILITY TITLE RISK
2022-01-10 CVE-2021-23154 OS Command Injection vulnerability in Mirantis Lens
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell.
network
mirantis CWE-78
critical
9.3
2022-01-10 CVE-2021-44458 Origin Validation Error vulnerability in Mirantis Lens
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website.
network
high complexity
mirantis CWE-346
5.1