A Remote Code Execution (RCE) vulnerability could be exploited by users with 'Write' access to the 'Deploy Agent' action in the UI. This has been fixed now.
This vulnerability allows users with 'Write' access to execute custom arbitrary commands on target servers.
This issue has been fixed by introducing parameter validation checks to verify the parameters before initiating remote connection.
Source and Acknowledgements:
This vulnerability was reported by Daniel Santos .
Kindly our product support teams for further details, at the email address mentioned below:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
