Vulnerability Name:

CVE-2021-41133 (CCN-211115)

Assigned:2021-10-08
Published:2021-10-08
Updated:2023-07-17
Summary:
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.7 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H)
7.6 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): High
Availibility (A): High
8.8 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
7.7 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.4 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2021-41133

Source: security-advisories@github.com
Type: Mailing List, Third Party Advisory
security-advisories@github.com

Source: XF
Type: UNKNOWN
flatpak-cve202141133-sec-bypass(211115)

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: CCN
Type: Flatpak GIT Repository
CVE-2021-41133: Sandbox bypass via recent VFS-manipulating syscalls

Source: security-advisories@github.com
Type: Patch, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Mailing List, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Mailing List, Third Party Advisory
security-advisories@github.com

Source: security-advisories@github.com
Type: Third Party Advisory
security-advisories@github.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:flatpak:flatpak:1.8.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7885
    P
    flatpak-1.14.4-150500.1.3 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3268
    P
    libtiff5-32bit-4.0.9-44.30.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94807
    P
    python3-python-gnupg-0.4.7-150400.1.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94898
    P
    flatpak-1.12.5-150400.1.11 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:112241
    P
    flatpak-1.12.1-1.1 on GA media (Moderate)
    2022-01-17
    oval:com.redhat.rhsa:def:20214042
    P
    RHSA-2021:4042: flatpak security update (Important)
    2021-11-01
    oval:com.redhat.rhsa:def:20214044
    P
    RHSA-2021:4044: flatpak security update (Important)
    2021-11-01
    oval:org.opensuse.security:def:111100
    P
    Security update for flatpak (Important)
    2021-10-31
    oval:org.opensuse.security:def:101731
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:4227
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:117700
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:65316
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:1040
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:74319
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:108186
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:74384
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:101520
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:4162
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:65251
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:111752
    P
    Security update for flatpak (Important)
    2021-10-20
    BACK
    flatpak flatpak 1.8.2