Code Execution Vulnerability in StackStorm by StackStorm Technologies
CVE-2021-44657
8.8HIGH
What is CVE-2021-44657?
In versions of StackStorm prior to 3.6.0, the Jinja interpreter was not executed in sandbox mode. This configuration flaw allowed attackers to execute unsafe system commands, posing significant security risks. To enhance security, StackStorm has now made sandbox mode the default for Jinja to mitigate this vulnerability.
