Логотип exploitDog
bind:CVE-2021-3139
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-3139

Количество 9

Количество 9

ubuntu логотип

CVE-2021-3139

около 5 лет назад

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2021-3139

около 5 лет назад

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2021-3139

около 5 лет назад

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2021-3139

около 5 лет назад

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy ...

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0128-1

около 5 лет назад

Security update for tcmu-runner

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0097-1

около 5 лет назад

Security update for tcmu-runner

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0158-1

около 5 лет назад

Security update for tcmu-runner

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0093-1

около 5 лет назад

Security update for tcmu-runner

EPSS: Низкий
github логотип

GHSA-j364-gjm2-cwx8

больше 3 лет назад

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-3139

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.

CVSS3: 8.1
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-3139

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.

CVSS3: 8.1
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-3139

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.

CVSS3: 8.1
1%
Низкий
около 5 лет назад
debian логотип
CVE-2021-3139

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy ...

CVSS3: 8.1
1%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0128-1

Security update for tcmu-runner

1%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0097-1

Security update for tcmu-runner

1%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0158-1

Security update for tcmu-runner

1%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0093-1

Security update for tcmu-runner

1%
Низкий
около 5 лет назад
github логотип
GHSA-j364-gjm2-cwx8

In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу