CVE-2021-42969

Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.
References
Link Resource
https://yuaneuro.cn/anaconda/anaconda_command_execution.docx Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:anaconda:anaconda3:2021.05:*:*:*:*:*:*:*

Information

Published : 2022-05-13 05:15

Updated : 2022-05-23 11:58


NVD link : CVE-2021-42969

Mitre link : CVE-2021-42969


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

anaconda

  • anaconda3