Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-32062

Опубликовано: 06 мая 2021
Источник: debian
EPSS Низкий

Описание

MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mapserverfixed7.6.3-1~exp1experimentalpackage
mapserverfixed7.6.2-2package
mapserverignoredbullseyepackage
mapserverno-dsabusterpackage
mapserverpostponedstretchpackage

Примечания

  • https://github.com/mapserver/mapserver/issues/6313

  • https://github.com/MapServer/MapServer/pull/6314

  • https://github.com/mapserver/mapserver/commit/927ac97cb9ece305306b5ab2b5600d3afe8c1732 (branch-7-6)

  • https://github.com/mapserver/mapserver/commit/7db7cbb26b6bc6e651db268e9536836a56e6825a (branch-7-2)

  • https://github.com/mapserver/mapserver/commit/82a3eb5f6c8f75cedd095b909cc4990f3d8a99e1 (branch-7-0)

  • Fixed in 7.0.8, 7.2.3, 7.4.5, 7.6.3

EPSS

Процентиль: 70%
0.00672
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).

CVSS3: 5.3
nvd
больше 4 лет назад

MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).

CVSS3: 5.3
github
около 3 лет назад

MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).

EPSS

Процентиль: 70%
0.00672
Низкий