PT-2021-18099 · Alpine+1 · Alpine Linux Configuration Framework+1

Steaith

·

Published

2021-03-24

·

Updated

2024-06-15

·

CVE-2021-29133

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Alpine Linux Configuration Framework versions prior to 0.9.36
Description: The issue is related to a lack of verification in haserl, a component of Alpine Linux Configuration Framework. This allows local users to read the contents of any file on the filesystem.
Recommendations: For versions prior to 0.9.36, update to version 0.9.36 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-29133
OPENSUSE-SU-2021:1279-1
OPENSUSE-SU-2021_1279-1
OPENSUSE-SU-2024:10840-1

Affected Products

Alpine Linux Configuration Framework
Suse