Vulnerability Name: | CVE-2021-32610 (CCN-206016) | ||||||||||||||||||||||||
Assigned: | 2021-07-21 | ||||||||||||||||||||||||
Published: | 2021-07-21 | ||||||||||||||||||||||||
Updated: | 2022-01-01 | ||||||||||||||||||||||||
Summary: | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) 6.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-59 CWE-22 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-32610 Source: XF Type: UNKNOWN drupal-core-cve202132610-code-exec(206016) Source: MISC Type: Patch, Third Party Advisory https://github.com/pear/Archive_Tar/commit/7789ebb2f34f9e4adb3a4152ad0d1548930a9755 Source: MISC Type: Patch, Third Party Advisory https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4f Source: MISC Type: Release Notes, Third Party Advisory https://github.com/pear/Archive_Tar/releases/tag/1.4.14 Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20210726 [SECURITY] [DLA 2721-1] drupal7 security update Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-0c013f520c Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-c9c1f6e5c7 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-6cf271948a Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-8093e197f4 Source: CCN Type: SA-CORE-2021-004 Drupal core - Critical - Drupal core - Critical - Third-party libraries Source: CONFIRM Type: Third Party Advisory https://www.drupal.org/sa-core-2021-004 Source: CCN Type: IBM Security Bulletin 6483595 (API Connect) IBM API Connect is impacted by a vulnerability in Drupal core (CVE-2021-32610) Source: CCN Type: WhiteSource Vulnerability Database CVE-2021-32610 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |