celeryproject CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

celeryproject vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to celeryproject, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-23727 This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system. [email protected] 7.5 1.40% 2021-12-29 2024-11-21
CVE-2011-4356 Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid and --gid arguments to celerybeat, celeryd_detach, celeryd-multi, and celeryev, which allows local users to gain privileges via vectors involving crafted code that is executed by the worker process. [email protected] 6.9 0.05% 2011-12-05 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence