Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-32639

Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the `RegisterPeerAction` endpoint and the `AddChildDirectoryAction` endpoint are vulnerable to SSRF. This vulnerability may lead to credential leaks. Emissary version 7.0 contains a patch. As a workaround, disable network access to Emissary from untrusted sources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.8%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
References
Products affected by CVE-2021-32639
  • Nsa » Emissary » Version: 5.0.0
    cpe:2.3:a:nsa:emissary:5.0.0
  • Nsa » Emissary » Version: 5.1.0
    cpe:2.3:a:nsa:emissary:5.1.0
  • Nsa » Emissary » Version: 5.10.0
    cpe:2.3:a:nsa:emissary:5.10.0
  • Nsa » Emissary » Version: 5.11.0
    cpe:2.3:a:nsa:emissary:5.11.0
  • Nsa » Emissary » Version: 5.2.0
    cpe:2.3:a:nsa:emissary:5.2.0
  • Nsa » Emissary » Version: 5.3.0
    cpe:2.3:a:nsa:emissary:5.3.0
  • Nsa » Emissary » Version: 5.4.1
    cpe:2.3:a:nsa:emissary:5.4.1
  • Nsa » Emissary » Version: 5.5.0
    cpe:2.3:a:nsa:emissary:5.5.0
  • Nsa » Emissary » Version: 5.6.0
    cpe:2.3:a:nsa:emissary:5.6.0
  • Nsa » Emissary » Version: 5.7.0
    cpe:2.3:a:nsa:emissary:5.7.0
  • Nsa » Emissary » Version: 5.8.0
    cpe:2.3:a:nsa:emissary:5.8.0
  • Nsa » Emissary » Version: 5.9.0
    cpe:2.3:a:nsa:emissary:5.9.0
  • Nsa » Emissary » Version: 6.0.0
    cpe:2.3:a:nsa:emissary:6.0.0
  • Nsa » Emissary » Version: 6.1.0
    cpe:2.3:a:nsa:emissary:6.1.0
  • Nsa » Emissary » Version: 6.2.0
    cpe:2.3:a:nsa:emissary:6.2.0
  • Nsa » Emissary » Version: 6.3.0
    cpe:2.3:a:nsa:emissary:6.3.0
  • Nsa » Emissary » Version: 6.4.0
    cpe:2.3:a:nsa:emissary:6.4.0


Contact Us

Shodan ® - All rights reserved