CVE-2021-30828Resource Exposure in Apple Macos

CWE-668Resource Exposure5 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 87.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 19
Latest updateMay 24

Description

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local user may be able to read arbitrary files as root.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5apple/macosunspecified11.6+1
NVDapple/macos11.011.6
NVDapple/mac_os_x10.1510.15.6+1

🔴Vulnerability Details

2
GHSA
GHSA-mgg2-p2x6-83vp: This issue was addressed with improved checks2022-05-24
CVEList
CVE-2021-30828: This issue was addressed with improved checks2021-10-19

📋Vendor Advisories

2
Apple
CVE-2021-30828: macOS Big Sur 11.62021-09-13
Apple
CVE-2021-30828: Security Update 2021-005 Catalina2021-09-13
CVE-2021-30828 — Resource Exposure in Apple Macos | cvebase