CVE-2021-32610
drupal7 - security update
7.1
HIGH
CVSS 3.1
EPSS 3.0%
Description
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
How to fix CVE-2021-32610
To remediate CVE-2021-32610, upgrade the affected package to a fixed version below.
- Debian/drupal7—upgrade to 7.52-2+deb9u16 or later
- Debian/php-pear—no fix listed
- —upgrade to 8.9.17 or later
- —upgrade to 1.4.14 or later
Is CVE-2021-32610 being exploited?
Low — EPSS is 3.0%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 7.52-2+deb9u16
- from 0
- >= 8.0.0, < 8.9.17 | >= 9.1.0, < 9.1.11 | >= 9.2.0, < 9.2.2
- from 0, < 1.4.14
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |