CVE-2021-23727
published 2021-12-29CVE-2021-23727: This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata…
PriorityP351high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
3.88%
89.0th percentile
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| celeryproject | celery | < 5.2.2 | 5.2.2 |
| celeryproject | celery | >= 0 < 5.2.3-1 | 5.2.3-1 |
| celeryproject | celery | >= 0 < 5.2.3-1 | 5.2.3-1 |
| celeryproject | celery | >= 0 < 5.2.3-1 | 5.2.3-1 |
| celeryproject | celery | >= 0 < 5.2.2 | 5.2.2 |
| celeryproject | celery | >= unspecified < 5.2.2 | 5.2.2 |
| debian | celery | < celery 5.2.3-1 (bookworm) | celery 5.2.3-1 (bookworm) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OS Command Injection in celery
ghsa·2022-01-06
CVE-2021-23727 [HIGH] CWE-77 OS Command Injection in celery
OS Command Injection in celery
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.
OSV
OS Command Injection in celery
osv·2022-01-06
CVE-2021-23727 [HIGH] OS Command Injection in celery
OS Command Injection in celery
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.
OSV
CVE-2021-23727: This affects the package celery before 5
osv·2021-12-29·CVSS 7.5
CVE-2021-23727 [HIGH] CVE-2021-23727: This affects the package celery before 5
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.
Red Hat
celery: stored command injection vulnerability may allow privileges escalation
vendor_redhat·2021-12-29·CVSS 7.5
CVE-2021-23727 [HIGH] CWE-77 celery: stored command injection vulnerability may allow privileges escalation
celery: stored command injection vulnerability may allow privileges escalation
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.
A command injection vulnerability was found in the distributed task queue celery, which can lead to remote code execution. An attacker with access to backend results can reconstruct the exception class to act as a command payload which can be queried to the task to execute.
Package: celery (Red Hat Ansi
Debian
CVE-2021-23727: celery - This affects the package celery before 5.2.2. It by default trusts the messages ...
vendor_debian·2021·CVSS 7.5
CVE-2021-23727 [HIGH] CVE-2021-23727: celery - This affects the package celery before 5.2.2. It by default trusts the messages ...
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.
Scope: local
bookworm: resolved (fixed in 5.2.3-1)
bullseye: open
forky: resolved (fixed in 5.2.3-1)
sid: resolved (fixed in 5.2.3-1)
trixie: resolved (fixed in 5.2.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/celery/celery/blob/master/Changelog.rst%23522https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYXRGHWHD2WWMHBWCVD5ULVINPKNY3P5/https://snyk.io/vuln/SNYK-PYTHON-CELERY-2314953https://github.com/celery/celery/blob/master/Changelog.rst%23522https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYXRGHWHD2WWMHBWCVD5ULVINPKNY3P5/https://snyk.io/vuln/SNYK-PYTHON-CELERY-2314953
2021-12-29
Published