Skip to content

Command Injection vulnerability in the Setup Wizard

Moderate
piRGoif published GHSA-pf95-6h7q-q85x Jul 20, 2021

Package

No package listed

Affected versions

<2.7.4 <3.0.0

Patched versions

2.7.4, 3.0.0

Description

Impact

There is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path.

Patches

Fixed in 2.7.4 and 3.0.0

References

Combodo ref N°3412

Credits

Many thanks to Markus Wulftange / Code White GmbH for this report !

For more information

If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com

Severity

Moderate

CVE ID

CVE-2021-21406

Weaknesses

No CWEs