CVE-2021-31819

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-31819
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31819.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-31819
Aliases
Withdrawn
2024-09-03T04:41:08.905696Z
Published
2021-09-22T02:15:09Z
Modified
2024-09-03T03:48:45.481368Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.

References

Affected packages

Git / github.com/octopusdeploy/halibut

Affected ranges

Type
GIT
Repo
https://github.com/octopusdeploy/halibut
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.2.0.55
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.17
2.4.18
2.4.19
2.4.2
2.4.3
2.4.4
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.12
2.6.13
2.6.14
2.6.15
2.6.19
2.6.2
2.6.3
2.6.4
2.6.6
2.6.8

3.*

3.0.0
3.0.2
3.0.4

4.*

4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.2.0
4.2.1
4.2.11
4.2.2
4.2.3
4.2.4
4.2.7
4.2.8
4.2.9
4.3.0
4.3.1
4.3.12
4.3.13
4.3.14
4.3.15
4.3.16
4.3.17
4.3.18
4.3.19
4.3.2
4.3.21
4.3.22
4.3.23
4.3.24
4.3.25
4.3.26
4.3.26-ci0001
4.3.26-ci0002
4.3.27
4.3.27-ci0001
4.3.27-ci0002
4.3.27-ci0003
4.3.28
4.3.28-ci0001
4.3.29
4.3.29-ci0001
4.3.29-ci0002
4.3.3
4.3.30-ci0001
4.3.30-ci0003
4.3.30-ci0005
4.3.30-ci0007
4.3.30-ci0009
4.3.31
4.3.32
4.3.33
4.3.34
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6