CVE-2021-4326

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-4326
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-4326.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-4326
Aliases
Published
2023-03-01T08:15:10Z
Modified
2025-10-21T06:37:44.655363Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.

References

Affected packages

Git / github.com/zowe/api-layer

Affected ranges

Type
GIT
Repo
https://github.com/zowe/api-layer
Events

Affected versions

Zowe_1.*

Zowe_1.16.0
Zowe_1.17.0
Zowe_1.18.0
Zowe_1.19.0
Zowe_1.20.0
Zowe_1.21.1
Zowe_1.22.0
Zowe_1.23.0
Zowe_1.24.0
Zowe_1.25.0
Zowe_1.26.0
Zowe_1.27.0
Zowe_1.28.0

v0.*

v0.0.25

v1.*

v1.16.0
v1.17.0
v1.17.1
v1.18.0
v1.18.1
v1.19.0
v1.19.1
v1.19.2
v1.20.0
v1.20.1
v1.20.10
v1.20.14
v1.20.15
v1.20.16
v1.20.18
v1.20.19
v1.21.10
v1.21.11
v1.21.12
v1.21.13
v1.21.2
v1.21.3
v1.21.4
v1.21.5
v1.21.6
v1.21.8
v1.21.9
v1.22.0
v1.22.1
v1.22.2
v1.22.3
v1.22.4
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.23.4
v1.23.5
v1.23.6
v1.23.7
v1.23.8
v1.24.0
v1.24.2
v1.24.3
v1.24.4
v1.24.5
v1.24.6
v1.24.7
v1.25.0
v1.25.1
v1.25.2
v1.25.3
v1.25.4
v1.25.5
v1.25.6
v1.25.7
v1.26.0
v1.26.1
v1.26.13
v1.26.15
v1.26.16
v1.26.17
v1.26.18
v1.26.19
v1.26.2
v1.26.20
v1.26.3
v1.26.4
v1.26.5
v1.26.6
v1.26.7
v1.26.8
v1.26.9
v1.27.11
v1.27.13
v1.27.15
v1.27.16
v1.27.17
v1.27.18
v1.27.19
v1.27.2
v1.27.20
v1.27.21
v1.27.22
v1.27.23
v1.27.24
v1.27.25
v1.27.26
v1.27.3
v1.27.4
v1.27.5
v1.28.0
v1.28.1