Back to Labs
Security Advisory

CVE-2021-41790

About

An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.

Rainforest analyst review

Alfresco Content Services lets a script action execute scripts that were uploaded outside the Data Dictionary, so a logged-in user can run arbitrary code — but inside a sandboxed environment. Two qualifiers shape this precisely: the attacker must be authenticated, and the execution is confined to a sandbox rather than free rein on the host. It's an escape of the intended "only run scripts from the trusted Data Dictionary" boundary by an authorized user.

Because it requires a valid low-privileged login and lands in a sandbox, the realistic threat is an authenticated insider or a compromised user account escalating what they can do within the content platform, not an anonymous remote takeover. The value to an attacker is code execution against a document-management system that often holds sensitive business content and integrates with identity and storage systems — a strong pivot point — but the authentication requirement and sandboxing are meaningful brakes that keep this off the critical-panic tier.

Our angle is to weigh who holds accounts and whether the platform is externally reachable. We'd inventory Alfresco Content Services through 7.0.1.2, prioritizing instances exposed beyond the corporate network or with broad self-registration, since those widen the pool of "logged-in attackers." It patches on the vendor line; where that lags, we'd tighten who can invoke script actions and monitor for script execution originating outside the Data Dictionary as the abuse signature.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2021-41790?

An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.

How severe is CVE-2021-41790?

CVE-2021-41790 carries a CVSS 3.1 base score of 8.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 89 out of 100, in the critical band.

How is CVE-2021-41790 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2021-41790?

Public advisories list the following as affected: alfresco content services. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2021-41790?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email