Lucene search

K
cvelistSnykCVELIST:CVE-2021-23391
HistoryJun 07, 2021 - 8:40 p.m.

CVE-2021-23391 Arbitrary File Write via Archive Extraction (Zip Slip)

2021-06-0720:40:11
snyk
www.cve.org
2
cve-2021-23391
arbitrary file write
archive extraction
calipso
malicious module

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:F/RL:U/RC:C

EPSS

0.001

Percentile

16.0%

This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality.

CNA Affected

[
  {
    "product": "calipso",
    "vendor": "n/a",
    "versions": [
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:F/RL:U/RC:C

EPSS

0.001

Percentile

16.0%

Related for CVELIST:CVE-2021-23391