{"id":"UBUNTU-CVE-2021-23727","details":"This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.","modified":"2025-10-24T04:50:09Z","published":"2021-12-29T17:15:00Z","upstream":["CVE-2021-23727"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-23727"},{"type":"REPORT","url":"https://github.com/celery/celery/blob/master/Changelog.rst%23522"},{"type":"REPORT","url":"https://snyk.io/vuln/SNYK-PYTHON-CELERY-2314953"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-23727"}],"affected":[{"package":{"name":"celery","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/celery@3.1.6-1ubuntu1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.5.3-4ubuntu1","3.1.6-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"celeryd","binary_version":"3.1.6-1ubuntu1"},{"binary_name":"python-celery","binary_version":"3.1.6-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-23727.json"}},{"package":{"name":"celery","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/celery@3.1.20-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.18-1ubuntu1","3.1.20-1"],"ecosystem_specific":{"binaries":[{"binary_name":"celeryd","binary_version":"3.1.20-1"},{"binary_name":"python-celery","binary_version":"3.1.20-1"},{"binary_name":"python-celery-common","binary_version":"3.1.20-1"},{"binary_name":"python3-celery","binary_version":"3.1.20-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-23727.json"}},{"package":{"name":"celery","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/celery@4.1.0-2ubuntu1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.0.2-0ubuntu1","4.1.0-2ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"python-celery","binary_version":"4.1.0-2ubuntu1"},{"binary_name":"python-celery-common","binary_version":"4.1.0-2ubuntu1"},{"binary_name":"python3-celery","binary_version":"4.1.0-2ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-23727.json"}},{"package":{"name":"celery","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/celery@4.2.1-5ubuntu1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.2.1-5fakesync1","4.2.1-5ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"python-celery-common","binary_version":"4.2.1-5ubuntu1"},{"binary_version":"4.2.1-5ubuntu1","binary_name":"python3-celery"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-23727.json"}},{"package":{"name":"celery","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/celery@5.3.6-1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.1-1","5.3.4-1","5.3.6-1"],"ecosystem_specific":{"binaries":[{"binary_name":"celery","binary_version":"5.3.6-1"},{"binary_version":"5.3.6-1","binary_name":"python-celery-common"},{"binary_name":"python3-celery","binary_version":"5.3.6-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-23727.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}