CVE-2021-21706Path Traversal: '../filedir' in Group PHP

Severity
6.5MEDIUMNVD
CNA5.3
EPSS
0.5%
top 32.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateMay 24

Description

In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDphp/php7.3.07.3.31+2
CVEListV5php_group/php7.3.x7.3.31+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x4g4-47f7-vvq4: In PHP versions 72022-05-24
OSV
CVE-2021-21706: In PHP versions 72021-10-04
CVEList
ZipArchive::extractTo may extract outside of destination dir2021-10-04

📋Vendor Advisories

1
Debian
CVE-2021-21706: php7.4 - In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, i...2021
CVE-2021-21706 — Path Traversal: '../filedir' | cvebase