VulnerabilityModified
CVE-2021-29133
Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents of any file on the filesystem.
MEDIUM 5.5EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents of any file on the filesystem.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- haserl project/haserl
- Source
- cve@mitre.org
References
- https://github.com/rapid7/metasploit-framework/pull/14833Exploit, Patch, Third Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/14833/commits/5bf6b2d094deb22fa8183ce161b90cbe4fd40a70Patch, Third Party Advisory
- https://gitlab.alpinelinux.org/alpine/aports/-/issues/12539Issue Tracking, Vendor Advisory
- https://twitter.com/steaIth/status/1364940271054712842Third Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/14833Exploit, Patch, Third Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/14833/commits/5bf6b2d094deb22fa8183ce161b90cbe4fd40a70Patch, Third Party Advisory
- https://gitlab.alpinelinux.org/alpine/aports/-/issues/12539Issue Tracking, Vendor Advisory
- https://twitter.com/steaIth/status/1364940271054712842Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.