Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.
{ "versions": [ { "introduced": "0" }, { "fixed": "0.42.1" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44255.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "20200606" } ] } ]