{"id":"CVE-2019-12440","details":"The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.","modified":"2026-07-08T16:27:17.570721Z","published":"2019-05-29T16:29:00.700Z","references":[{"type":"ADVISORY","url":"https://github.com/Sitecore/Sitecore.Rocks/releases/tag/2.1.149"},{"type":"FIX","url":"https://github.com/Sitecore/Sitecore.Rocks/compare/be79dcc...bd9ba6a"},{"type":"FIX","url":"https://kb.sitecore.net/articles/842902"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sitecore/sitecore.rocks","events":[{"introduced":"0"},{"fixed":"bd9ba6a30fc41675c7ec0852c7a48cc25732f561"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:sitecore:rocks:*:*:*:*:*:sitecore:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.1.149"}]}}],"versions":["2.1.130","2.1.126","v2.1.69","2.1.86","2.1.69","2.0.59","2.0.54","2.0.39","2.0.32","1.5.1.7","1.5.0","1.4.0","1.3.5","1.3.1","1.3.0","1.2.6","1.2.5","1.2.0","1.1.0","v2.0.39","v2.0.0-32"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12440.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}