PT-2021-18099 · Alpine+1 · Alpine Linux Configuration Framework+1
Steaith
·
Published
2021-03-24
·
Updated
2024-06-15
·
CVE-2021-29133
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Alpine Linux Configuration Framework versions prior to 0.9.36
Description:
The issue is related to a lack of verification in haserl, a component of Alpine Linux Configuration Framework. This allows local users to read the contents of any file on the filesystem.
Recommendations:
For versions prior to 0.9.36, update to version 0.9.36 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alpine Linux Configuration Framework
Suse