CVE-2021-4430General(ortussolutions / coldbox_elixir)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information disclosure. Upgrading to version 3.1.7 is able to address this issue. The identifier of the patch is a3aa62daea2e44c76d08d1eac63768cd928cd69e. It is recommended to upgrade the affected component. The identifier VDB-244485 was assigned to this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldbox_elixir

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
coldbox_elixir

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-26: 2Technical Details · 2026-03-26: 103-26
Signal classification1 categories
General
2100.0%
Full discourse2 posts
  • Borne Systems@BorneSystems
    General

    🚨 CVE-2021-4430 is a local privilege escalation vulnerability in sudo, impacting systems with specific configurations. Let’s break down how to exploit and detect it! #OSCP #CyberSecurity

    Post summary

    The post identifies CVE‑2021‑4430 as a local privilege escalation flaw in sudo, but offers no proof of concept, exploit tool, active exploitation evidence, patch, or debunking details.

    1000046
    4 followersView on X
  • Borne Systems@BorneSystems
    General

    Want to sharpen your skills? Dive deeper into CVE-2021-4430 and enumeration techniques with Borne Systems. Let’s advance your pentesting game! #OSCP

    Post summary

    The tweet promotes learning about CVE-2021-4430 and enumeration techniques but provides no technical, exploit, or mitigation details.

    0000045
    4 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apportussolutionscoldbox_elixir3.1.6--

Explore more