Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-24031

Опубликовано: 11 фев. 2021
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

A flaw was found in zstd. While the final file mode is reflective of the input file, when compressing or uncompressing, the file can temporarily gain greater permissions than the input and potentially leading to security issues (especially if large files are being handled).

Отчет

In OpenShift Container Platform (OCP) the zstd package was delivered in OCP 4.3 which is already end of life.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 3cephAffected
Red Hat Enterprise Linux 8zstdNot affected
Red Hat Enterprise Linux 9zstdNot affected
Red Hat OpenShift Container Platform 4zstdOut of support scope
Red Hat OpenStack Platform 16.1zstdNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-281
https://bugzilla.redhat.com/show_bug.cgi?id=1934852zstd: adds read permissions to files while being compressed or uncompressed

EPSS

Процентиль: 22%
0.00074
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 5 лет назад

In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

CVSS3: 5.5
nvd
почти 5 лет назад

In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

CVSS3: 5.5
debian
почти 5 лет назад

In the Zstandard command-line utility prior to v1.4.1, output files we ...

github
больше 3 лет назад

In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

CVSS3: 5.5
fstec
больше 6 лет назад

Уязвимость библиотеки для сжатия данных Zstandard, связанная с настройками прав доступа по умолчанию, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 22%
0.00074
Низкий

5.5 Medium

CVSS3