CVE-2021-29133 Information

Description

Lack of verification in haserl a component of Alpine Linux Configuration Framework before 0.9.36 allows local users to read the contents of any file on the filesystem.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Reference

https://twitter.com/steaIth/status/1364940271054712842 https://gitlab.alpinelinux.org/alpine/aports/-/issues/12539 https://github.com/rapid7/metasploit-framework/pull/14833/commits/5bf6b2d094deb22fa8183ce161b90cbe4fd40a70 https://github.com/rapid7/metasploit-framework/pull/14833

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

5.5

Share on: