CVE-2021-21707
In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.
Published
2021-11-29T07:15:06.397
Last Modified
2024-11-21T05:48:52.593
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 5.3 (MEDIUM)
CVSSv2 Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: PARTIAL
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
10.0
Impact Score
2.9
Weaknesses
-
Type: Secondary
CWE-159
-
Type: Primary
NVD-CWE-Other
Affected Vendors & Products
References
-
https://bugs.php.net/bug.php?id=79971
Exploit, Issue Tracking, Patch, Release Notes, Vendor Advisory
([email protected])
-
https://lists.debian.org/debian-lts-announce/2022/12/msg00030.html
Issue Tracking, Mailing List
([email protected])
-
https://security.netapp.com/advisory/ntap-20211223-0005/
Third Party Advisory
([email protected])
-
https://www.debian.org/security/2022/dsa-5082
Third Party Advisory
([email protected])
-
https://www.tenable.com/security/tns-2022-09
Patch, Release Notes, Third Party Advisory
([email protected])
-
https://bugs.php.net/bug.php?id=79971
Exploit, Issue Tracking, Patch, Release Notes, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://lists.debian.org/debian-lts-announce/2022/12/msg00030.html
Issue Tracking, Mailing List
(af854a3a-2127-422b-91ae-364da2661108)
-
https://security.netapp.com/advisory/ntap-20211223-0005/
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://www.debian.org/security/2022/dsa-5082
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://www.tenable.com/security/tns-2022-09
Patch, Release Notes, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)