CVE-2021-22961

A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in the user path on first execution.
References
Link Resource
https://hackerone.com/reports/1193641 Permissions Required
Configurations

Configuration 1 (hide)

cpe:2.3:a:glasswire:glasswire:2.1.167:*:*:*:*:*:*:*

History

21 Oct 2021, 22:53

Type Values Removed Values Added
CPE cpe:2.3:a:glasswire:glasswire:2.1.167:*:*:*:*:*:*:*
References (MISC) https://hackerone.com/reports/1193641 - (MISC) https://hackerone.com/reports/1193641 - Permissions Required
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CWE CWE-94

18 Oct 2021, 13:39

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-18 13:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-22961

Mitre link : CVE-2021-22961

CVE.ORG link : CVE-2021-22961


JSON object : View

Products Affected

glasswire

  • glasswire
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')