Description
Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid and --gid arguments to celerybeat, celeryd_detach, celeryd-multi, and celeryev, which allows local users to gain privileges via vectors involving crafted code that is executed by the worker process.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-0002 | Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid and --gid arguments to celerybeat, celeryd_detach, celeryd-multi, and celeryev, which allows local users to gain privileges via vectors involving crafted code that is executed by the worker process. |
Github GHSA |
GHSA-rpc6-h455-3rx5 | Celery local privilege escalation vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T00:09:18.439Z
Reserved: 2011-11-04T00:00:00.000Z
Link: CVE-2011-4356
No data.
Status : Deferred
Published: 2011-12-05T11:55:07.380
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-4356
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA