SB2021052127 - Deserialization of Untrusted Data in emissary
Published: May 21, 2021 Updated: April 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Deserialization of Untrusted Data (CVE-ID: CVE-2021-32634)
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in the WorkSpaceClientEnqueue.action REST endpoint when processing post-authenticated requests. A remote privileged user can send a specially crafted serialized request to execute arbitrary code.
Since version 6.3.0, the endpoint is protected against CSRF attacks, which reduces the impact of the vulnerability.
Remediation
Install update from vendor's website.