{"id":"CVE-2021-21009","title":"Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability","summary":"Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Su…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-918"],"vendor":"adobe","product":"campaign","affected":["campaign < 19.1.8","campaign >= 19.2, < 19.2.4","campaign >= 20.1, < 20.1.4","campaign >= 20.2, < 20.2.4","campaign >= 20.3, < 20.3.3"],"patched":["campaign 20.3.3"],"published":"2021-01-13","updated":"2026-08-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-21009","references":[{"url":"https://helpx.adobe.com/security/products/campaign/apsb21-04.html","label":"psirt@adobe.com"},{"url":"https://helpx.adobe.com/security/products/campaign/apsb21-04.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0299,"epssPercentile":0.86803,"ingestedAt":"2026-08-24T18:09:08.423Z","slug":"CVE-2021-21009","body":"## Overview\n\nAdobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources.\n\n## Affected\n\n- `campaign < 19.1.8`\n- `campaign >= 19.2, < 19.2.4`\n- `campaign >= 20.1, < 20.1.4`\n- `campaign >= 20.2, < 20.2.4`\n- `campaign >= 20.3, < 20.3.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `campaign 20.3.3`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.3,"likelihood":0.6,"exploitation":0,"ransomware":0},"changes":[]}