A Remote Code Execution (RCE) vulnerability exists in Algorithmia MSOL all versions before October 10 2021 of SaaS. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new, specially crafted Algorithm and subsequently launch remote code execution with their desired result.
References
Link Resource
http://algorithmia.com Vendor Advisory
https://seclists.org/fulldisclosure/2022/Feb/33 Mailing List Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-03-01T01:40:31

Updated: 2022-03-01T01:40:31

Reserved: 2021-10-25T00:00:00


Link: CVE-2021-42951

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-01T02:15:07.417

Modified: 2022-03-10T14:31:38.043


Link: CVE-2021-42951

JSON object: View

cve-icon Redhat Information

No data.