Command injection in Lens causes arbitrary shell command execution when malicious custom helm chart configuration provided
Vulnerability Description
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary shell commands to run on the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-23154
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Eren Karahasan (locomoco.dev@gmail.com)
More from Mirantis
View All →Affected Vendor
Mirantis
View all reports →