CVE-2021-21706

In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.
References
Link Resource
https://bugs.php.net/bug.php?id=81420 Issue Tracking Patch Vendor Advisory
https://security.netapp.com/advisory/ntap-20211029-0007/ Third Party Advisory
https://bugs.php.net/bug.php?id=81420 Issue Tracking Patch Vendor Advisory
https://security.netapp.com/advisory/ntap-20211029-0007/ Third Party Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:48

Type Values Removed Values Added
CVSS v2 : 4.3
v3 : 6.5
v2 : 4.3
v3 : 5.3
References () https://bugs.php.net/bug.php?id=81420 - Issue Tracking, Patch, Vendor Advisory () https://bugs.php.net/bug.php?id=81420 - Issue Tracking, Patch, Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20211029-0007/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20211029-0007/ - Third Party Advisory

03 Nov 2021, 20:24

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20211029-0007/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20211029-0007/ - Third Party Advisory

29 Oct 2021, 13:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20211029-0007/ -

08 Oct 2021, 15:29

Type Values Removed Values Added
CWE CWE-22
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
References (CONFIRM) https://bugs.php.net/bug.php?id=81420 - (CONFIRM) https://bugs.php.net/bug.php?id=81420 - Issue Tracking, Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.5

04 Oct 2021, 05:15

Type Values Removed Values Added
Summary In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions. In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.

04 Oct 2021, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-04 04:15

Updated : 2024-11-21 05:48


NVD link : CVE-2021-21706

Mitre link : CVE-2021-21706

CVE.ORG link : CVE-2021-21706


JSON object : View

Products Affected

php

  • php

microsoft

  • windows
CWE
CWE-24

Path Traversal: '../filedir'

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')