CVE-2021-32610

HIGH7.1EPSS 3.0%

drupal7 - security update

發布日:2021/7/21修改日:2026/3/9
也稱為:GHSA-p8q8-jfcv-g2h2DEBIAN-CVE-2021-32610DLA-2721-1DRUPAL-CORE-2021-004

描述

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

參考連結(12)