Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbitrary code within the Code Agent container. Exploiting this vulnerability would require an attacker to have network access to the Code Agent within the deployment environment. External exploitation of this vulnerability is unlikely and depends on both misconfigurations of the cluster and/or chaining with another vulnerability. However, internal exploitation (with a cluster misconfiguration) could still be possible.
History

Fri, 06 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Synk
Synk code Agent
CPEs cpe:2.3:a:synk:code_agent:*:*:*:*:*:*:*:*
Vendors & Products Synk
Synk code Agent
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Dec 2024 13:30:00 +0000

Type Values Removed Values Added
Description Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbitrary code within the Code Agent container. Exploiting this vulnerability would require an attacker to have network access to the Code Agent within the deployment environment. External exploitation of this vulnerability is unlikely and depends on both misconfigurations of the cluster and/or chaining with another vulnerability. However, internal exploitation (with a cluster misconfiguration) could still be possible.
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2024-12-06T13:21:11.671Z

Updated: 2024-12-06T17:54:30.794Z

Reserved: 2023-12-22T12:33:20.130Z

Link: CVE-2024-21571

cve-icon Vulnrichment

Updated: 2024-12-06T17:54:25.689Z

cve-icon NVD

Status : Received

Published: 2024-12-06T14:15:19.997

Modified: 2024-12-06T14:15:19.997

Link: CVE-2024-21571

cve-icon Redhat

No data.