Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the checkout_repo function is called on a maliciously crafted file. An attacker can leverage this to execute arbitrary code on the victim machine.
References
Link Resource
https://helpx.adobe.com/security/products/ops_cli/apsb21-88.html Patch Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: adobe

Published: 2021-10-12T00:00:00

Updated: 2021-10-15T14:22:00

Reserved: 2021-09-08T00:00:00


Link: CVE-2021-40720

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-10-15T15:15:08.530

Modified: 2021-10-20T20:36:06.337


Link: CVE-2021-40720

JSON object: View

cve-icon Redhat Information

No data.

CWE