{"id":"CVE-2021-39172","details":"Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. This issue was addressed in version 2.5.1 by improving `UpdateConfigCommandHandler` and preventing the use of new lines characters in new configuration values. As a workaround, only allow trusted source IP addresses to access to the administration dashboard.","aliases":["GHSA-9jxw-cfrh-jxq6"],"modified":"2026-08-07T19:47:02.198167Z","published":"2021-08-27T23:15:06.900Z","references":[{"type":"ADVISORY","url":"https://github.com/fiveai/Cachet/releases/tag/v2.5.1"},{"type":"ADVISORY","url":"https://github.com/fiveai/Cachet/security/advisories/GHSA-9jxw-cfrh-jxq6"},{"type":"EVIDENCE","url":"https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fiveai/cachet","events":[{"introduced":"0"},{"fixed":"d7ecabfb5db4872470508671348408b14abcadcb"}],"database_specific":{"cpe":"cpe:2.3:a:catchethq:catchet:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.5.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.5.0","v2.3.0-RC5","v2.3.0-RC4","v2.3.0-RC3","v2.3.0-RC2","v2.3.0-RC1","v2.2.0","v2.2.0-RC1","v2.1.1","v2.1.0","v2.1.0-RC2","v2.1.0-RC1","v2.0.2","v2.0.1","v2.0.0","v2.0.0-RC5","v2.0.0-RC4","v2.0.0-RC3","v2.0.0-RC2","v2.0.0-RC1","v2.0.0-beta2","v2.0.0-beta1","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-39172.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}