CVE-2021-43757
published 2023-07-12CVE-2021-43757: Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.33%
24.9th percentile
Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious 3GP file
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | media_encoder | < 15.4.3 | 15.4.3 |
| adobe | media_encoder | <= 15.4.2 | — |
| adobe | media_encoder | — | — |
| github.com | rancher_rancher | >= 2.5.0 < 2.5.17 | 2.5.17 |
| github.com | rancher_rancher | >= 2.6.0 < 2.6.10 | 2.6.10 |
| github.com | rancher_rancher | >= 2.7.0 < 2.7.1 | 2.7.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-399f-937r-fwr9: Adobe Media Encoder versions 22
ghsa_unreviewed·2023-07-12
CVE-2021-43757 [HIGH] CWE-125 GHSA-399f-937r-fwr9: Adobe Media Encoder versions 22
Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious 3GP ?file
GHSA
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects
ghsa·2023-01-25·CVSS 9.9
CVE-2022-43757 [CRITICAL] CWE-200 Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects
### Impact
This issue affects Rancher versions from 2.5.0 up to and including 2.5.16, from 2.6.0 up to and including 2.6.9 and 2.7.0. It was discovered that the security advisory CVE-2021-36782 (GHSA-g7j7-h4q8-8w2f), previously released by Rancher, missed addressing some sensitive fields, secret tokens, encryption keys, and SSH keys that were still being stored in plaintext directly on Kubernetes objects like `Clusters`.
The exposed credentials are visible in Rancher to authenticated `Cluster Owners`, `Cluster Members`, `Project Owners` and `Project Members` of that cluster on the endpoints:
- `/v1/management.cattle.io.cluster`
- `/v1/management.cattle.io.clustertemplaterevisions`
The remaining
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-12
Published