Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-47935

Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with base64-encoded compressed pickle payloads in the data field to achieve code execution with application privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2021-47935
  • Sentry » Sentry » Version: 8.2.0
    cpe:2.3:a:sentry:sentry:8.2.0


Contact Us

Shodan ® - All rights reserved