VYPR
Unrated severityNVD Advisory· Published Jun 10, 2021· Updated Aug 4, 2024

CVE-2021-34539

CVE-2021-34539

Description

An issue was discovered in CubeCoders AMP before 2.1.1.8. A lack of validation of the Java Version setting means that an unintended executable path can be set. The result is that high-privileged users can trigger code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A lack of validation in CubeCoders AMP's Java Version setting before 2.1.1.8 allows high-privileged users to set arbitrary executable paths, enabling code execution.

Vulnerability

CubeCoders AMP versions before 2.1.1.8 have an insufficient validation flaw in the Java Version setting [1]. This configuration parameter does not properly validate the provided path, allowing a non-default executable to be specified. The setting is intended to control which Java binary is used, but the lack of checks means any file system path can be supplied [1].

Exploitation

An attacker with high-privileged access (e.g., admin-level users who can modify instance settings) can exploit this by using a browser's Inspect Element tool to alter the Java Version field to a path to a malicious executable [1]. No additional authentication bypass is required because the attacker already has sufficient privileges to edit AMP settings [1]. The exploit does not require any race condition or user interaction beyond the attacker's own actions [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code on the server with the privileges of the AMP process [1]. This can lead to full compromise of the host system, although instances running inside Docker are not affected as the execution would be confined to the container [1]. The impact is potentially high, but the risk is considered low because only already high-privileged users can trigger the issue [1].

Mitigation

A fix was released on the same day as the report (10/06/2021) and is included in AMP version 2.1.1.8 [1]. All users should upgrade to this version or later. For instances running inside Docker, the impact is limited, but upgrading is still recommended [1]. No workarounds beyond upgrading are documented in the available references [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • CubeCoders/AMPdescription
  • CubeCoders/AMPllm-create
    Range: < 2.1.1.8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.