cbcvebase.
CVE-2021-20316
published 2022-08-23

CVE-2021-20316: A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share…

PriorityP336medium6.8CVSS 3.1
AVNACHPRLUINSUCHIHAN
EPSS
0.76%
51.2th percentile
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiansamba< samba 2:4.16.0+dfsg-2 (bookworm)samba 2:4.16.0+dfsg-2 (bookworm)
msrcazl3_samba_4.18.3-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
redhatenterprise_linux
redhatenterprise_linux_aus
redhatenterprise_linux_eus
redhatenterprise_linux_tus
redhatvirtualization_host
sambasamba< 4.15.04.15.0
sambasamba
sambasamba>= 0 < 2:4.16.0+dfsg-22:4.16.0+dfsg-2
sambasamba>= 0 < 2:4.16.0+dfsg-22:4.16.0+dfsg-2
sambasamba>= 0 < 2:4.16.0+dfsg-22:4.16.0+dfsg-2

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_msrc6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.