CVE-2021-30070 is a high-severity vulnerability affecting HestiaCP versions prior to 1.3.5, allowing unauthenticated attackers to arbitrarily install packages. This is due to improper sanitization of the 'pkg' parameter in update requests, which is directly passed to the operating system's package manager. With a CVSS score of 7.5, this vulnerability presents a significant integrity impact, as attackers can compromise system integrity by installing malicious software. There is currently no evidence of active exploitation, nor are public exploit codes or Metasploit modules available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.5CPE matchmatch criteria | cpe:2.3:a:hestiacp:hestiacp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.