CVE detail
CVE-2021-23154 — CVE-2021-23154
Published 2022-01-10 · Modified 2026-06-17 · Vendor mirantis · Product lens · Source nvd
MEDIUM
severity
CVSS-derived band
0.0060
EPSS probability
exploitation probability, 30d
46.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary shell commands to run on the system.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References