Arbitrary Shell Command Execution in Lens Prior to 5.3.4

Arbitrary Shell Command Execution in Lens Prior to 5.3.4

CVE-2021-23154 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary shell commands to run on the system.

Learn more about our User Device Pen Test.