CVE-2021-41269
Description
cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no known workarounds known.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.cronutils:cron-utilsMaven | < 9.1.6 | 9.1.6 |
Affected products
3- Range: < 9.1.6
Patches
Vulnerability mechanics
References
6- github.com/jmrozanec/cron-utils/commit/cfd2880f80e62ea74b92fa83474c2aabdb9899danvdPatchThird Party AdvisoryWEB
- github.com/jmrozanec/cron-utils/commit/d6707503ec2f20947f79e38f861dba93b39df9danvdPatchThird Party AdvisoryWEB
- github.com/jmrozanec/cron-utils/issues/461nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-p9m8-27x8-rg87ghsaADVISORY
- github.com/jmrozanec/cron-utils/security/advisories/GHSA-p9m8-27x8-rg87nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-41269ghsaADVISORY
News mentions
0No linked articles in our index yet.