5.5
CVE-2021-29133
- EPSS 1.08%
- Veröffentlicht 24.03.2021 07:15:13
- Zuletzt bearbeitet 21.11.2024 06:00:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents of any file on the filesystem.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haserl Project ≫ Haserl Version < 0.9.36
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.08% | 0.608 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
https://github.com/rapid7/metasploit-framework/pull/14833
https://github.com/rapid7/metasploit-framework/pull/14833/commits/5bf6b2d094deb22fa8183ce161b90cbe4fd40a70
https://gitlab.alpinelinux.org/alpine/aports/-/issues/12539
https://twitter.com/steaIth/status/1364940271054712842