Deserialization of Untrusted Data in Emissary
CVE-2021-32634
7.2HIGH
What is CVE-2021-32634?
Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the WorkSpaceClientEnqueue.action REST endpoint. This issue may lead to post-auth Remote Code Execution. This issue has been patched in version 6.5.0. As a workaround, one can disable network access to Emissary from untrusted sources.
Affected Version(s)
emissary < 6.5.0
