Vulnerability Name:

CVE-2021-21300 (CCN-197283)

Assigned:2020-12-22
Published:2021-03-09
Updated:2022-12-06
Summary:
CVSS v3 Severity:8.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N)
7.4 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): None
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
8.2 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2021-21300

Source: security-advisories@github.com
Type: Exploit, Third Party Advisory, VDB Entry
security-advisories@github.com

Source: security-advisories@github.com
Type: Mailing List, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Exploit, Mailing List, Third Party Advisory
security-advisories@github.com

Source: XF
Type: UNKNOWN
ms-vs-cve202121300-code-exec(197283)

Source: security-advisories@github.com
Type: Vendor Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Vendor Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: CCN
Type: git GIT Repository
malicious repositories can execute remote code while cloning

Source: security-advisories@github.com
Type: Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Mailing List, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Mailing List, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Mailing List, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Release Notes, Third Party Advisory
security-advisories@github.com

Source: CCN
Type: Packet Storm Security [08-31-2021]
Git LFS Clone Command Execution

Source: CCN
Type: Microsoft Security TechCenter - March 2021
Git for Visual Studio Remote Code Execution Vulnerability

Source: security-advisories@github.com
Type: Third Party Advisory
security-advisories@github.com

Source: CCN
Type: Apple security document HT212320
About the security content of Xcode 12.5

Source: security-advisories@github.com
Type: Third Party Advisory
security-advisories@github.com

Source: CCN
Type: IBM Security Bulletin 6610343 (Watson Speech Services Cartridge for Cloud Pak for Data)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data is vulnerable to arbitrary code execution in MS Visual Studio (CVE-2021-21300).

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:git-scm:git:2.14.2:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:visual_studio_2017:15.9:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:visual_studio_2019:16.4:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:visual_studio_2019:16.7:*:*:*:*:*:*:*
  • OR cpe:/o:apple:macos_big_sur:11.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:visual_studio_2019:16.8:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:visual_studio_2019:16.9:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8009
    P
    git-2.35.3-150300.10.27.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7507
    P
    git-core-2.35.3-150300.10.27.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:748
    P
    Security update for samba (Important)
    2022-09-12
    oval:org.opensuse.security:def:3649
    P
    Security update for u-boot (Important) (in QA)
    2022-08-04
    oval:org.opensuse.security:def:6112
    P
    Security update for xen (Important)
    2022-07-27
    oval:org.opensuse.security:def:3577
    P
    libass5-0.10.2-3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3384
    P
    tomcat-9.0.21-3.13.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94562
    P
    git-core-2.35.3-150300.10.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95014
    P
    git-2.35.3-150300.10.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94689
    P
    libpolkit0-0.116-3.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2932
    P
    git-core-2.35.3-150300.10.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94949
    P
    libjasper-devel-2.0.14-150000.3.25.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:995
    P
    Security update for containerd, docker and runc (Important) (in QA)
    2022-06-14
    oval:org.opensuse.security:def:66
    P
    git-core-2.26.2-3.31.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:4567
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 12 SP5) (Important)
    2022-04-13
    oval:org.opensuse.security:def:101662
    P
    Security update for java-11-openjdk (Moderate)
    2022-03-14
    oval:org.opensuse.security:def:93327
    P
    (Important)
    2022-03-10
    oval:org.opensuse.security:def:99217
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:102231
    P
    Security update for virglrenderer (Important)
    2022-01-18
    oval:org.opensuse.security:def:112298
    P
    git-2.33.0-1.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:112299
    P
    git-annex-8.20210903-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:4540
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 12 SP5) (Important)
    2021-12-14
    oval:org.opensuse.security:def:105821
    P
    git-2.33.0-1.3 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:105822
    P
    git-annex-8.20210903-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:99414
    P
    (Low)
    2021-09-07
    oval:org.opensuse.security:def:101402
    P
    spice-gtk-devel-0.38-1.59 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:101265
    P
    git-2.26.2-3.31.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1918
    P
    git-2.26.2-3.31.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62084
    P
    git-core-2.26.2-3.31.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71825
    P
    git-core-2.26.2-3.31.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100842
    P
    git-core-2.26.2-3.31.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63007
    P
    git-2.26.2-3.31.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72726
    P
    git-2.26.2-3.31.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:74724
    P
    Security update for git (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:111643
    P
    Security update for git (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:101479
    P
    Security update for git (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:64738
    P
    Security update for git (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:73860
    P
    Security update for git (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:67201
    P
    Security update for git (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:76269
    P
    Security update for git (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:101794
    P
    Security update for git (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:65656
    P
    Security update for git (Moderate)
    2021-07-29
    oval:org.opensuse.security:def:111260
    P
    Security update for git (Important)
    2021-03-14
    oval:org.opensuse.security:def:33093
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:55306
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:95518
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:26208
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:92663
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:108068
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:10220
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:69804
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:99613
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:97280
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:64666
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:88263
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:58094
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:83245
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:117842
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:31355
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:51746
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:23189
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:73788
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:92072
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:9466
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:67059
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:99022
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:60475
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:86206
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:33782
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:55861
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:81117
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:28950
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:76127
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:92862
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:108328
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:10414
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:70003
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:99812
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:8717
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:88580
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:58916
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:84281
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:125669
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:31742
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:52024
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:23758
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:92267
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:9664
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:86735
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:34040
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:57178
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:82157
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:5195
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:29483
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:93021
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:108897
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:70360
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:100124
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:8911
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:65629
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:89260
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:59605
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:84739
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:126836
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:32271
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:54773
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:24036
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:74697
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:92464
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:9863
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:69606
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:5970
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:87557
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:34652
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:57565
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:82690
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:117582
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:30038
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:51177
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:93174
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:21423
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:70554
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:9106
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:89518
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:59863
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:85819
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:127233
    P
    Security update for git (Important)
    2021-03-09
    BACK
    git-scm git 2.14.2
    microsoft visual studio 2017 15.9
    microsoft visual studio 2019 16.4
    microsoft visual studio 2019 16.7
    apple macos big sur 11.0.0
    microsoft visual studio 2019 16.8
    microsoft visual studio 2019 16.9