← Back to the feed

~/article/kestra-oss-os-command-injection-vulnerability-1xr2l4
criticalSource: CISA

Kestra OSS OS Command Injection Vulnerability

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Read at the source

Summary written for cymesh.dev. The full article lives at CISA.

Referenced CVEs

Topics

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/kestra-oss-os-command-injection-vulnerability-1xr2l4