{"id":"CVE-2021-32639","details":"Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the `RegisterPeerAction` endpoint and the `AddChildDirectoryAction` endpoint are vulnerable to SSRF. This vulnerability may lead to credential leaks. Emissary version 7.0 contains a patch. As a workaround, disable network access to Emissary from untrusted sources.","aliases":["GHSA-2p8j-2rf3-h4xr"],"modified":"2026-07-09T10:01:31.583015Z","published":"2021-07-02T16:15:08.967Z","references":[{"type":"EVIDENCE","url":"https://github.com/NationalSecurityAgency/emissary/blob/30c54ef16c6eb6ed09604a929939fb9f66868382/src/main/java/emissary/server/mvc/internal/AddChildDirectoryAction.java"},{"type":"EVIDENCE","url":"https://github.com/NationalSecurityAgency/emissary/blob/30c54ef16c6eb6ed09604a929939fb9f66868382/src/main/java/emissary/server/mvc/internal/RegisterPeerAction.java"},{"type":"EVIDENCE","url":"https://github.com/NationalSecurityAgency/emissary/security/advisories/GHSA-2p8j-2rf3-h4xr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nationalsecurityagency/emissary","events":[{"introduced":"0"},{"last_affected":"0be7265fdfa51f0c0b4e70598a234fc2c0ccdf7b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"6.4.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:nsa:emissary:*:*:*:*:*:*:*:*"}}],"versions":["6.4.0","6.3.0","6.2.0","6.1.0","6.0.0","5.11.0","5.10.0","5.9.0","5.8.0","5.7.0","5.6.0","5.5.0","5.4.1","5.3.0","5.2.0","5.1.0","5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32639.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}