** UNSUPPORTED WHEN ASSIGNED ** In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2021-46703 - High Severity Vulnerability
Vulnerable Library - RazorEngine-3.4.1.0.dll
RazorEngine.Core
Library home page: https://api.nuget.org/packages/razorengine.3.4.1.nupkg
Path to vulnerable library: /node_modules/gherkin/berp/RazorEngine.dll
Dependency Hierarchy: - :x: **RazorEngine-3.4.1.0.dll** (Vulnerable Library)
Found in base branch: master
Vulnerability Details
** UNSUPPORTED WHEN ASSIGNED ** In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Publish Date: 2022-03-06
URL: CVE-2021-46703
CVSS 3 Score Details (9.8)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2021-46703
Release Date: 2022-03-06
Fix Resolution: Bddify - 0.3.1;SpecRun - 1.0.0;S-money.Api.Wrapper - 1.0.2.3-alpha;graze - 5.5.0;ExtentReports - 2.40.1-beta4;Wolfpack.Contrib.Publishers.Email - 3.0.20,3.0.10-pre;Zapos.Common - 1.13.1.38,1.13.1;ExcelDnaDoc - 0.1.3-alpha,1.5.0-rc;FSharp.Formatting.CommandTool - 2.7.5,2.6.2;gcRazor - 1.0.8;BitFrame - 0.0.0.4;Zapos.Printers.Gembox - 1.13.1,1.13.1.41;FSharp.Formatting - 2.6.2,2.7.5;Cake.MarkdownToPdf - 0.4.0,0.3.0;Zapos.Constructors.Razor - 1.13.1,1.13.1.41;BDDify - 0.2.0;bddify - 0.3.0;apitize - 1.0.10;Berp - 1.3.0;Yaaf.AdvancedBuilding - 0.5.0;SpecRun.Runner - 1.6.0-rc005;Postal-Custom.Mvc5 - 1.0.1
Step up your Open Source Security Game with Mend here