CVE-2021-32062Path Traversal in Mapserver

Severity
5.3MEDIUMNVD
EPSS
1.1%
top 21.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 24

Description

MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDosgeo/mapserver7.1.07.2.3+3
debiandebian/mapserver< mapserver 7.6.2-2 (bookworm)
Debianosgeo/mapserver< 7.6.2-1+deb11u1+3

Also affects: Fedora 33, 34

🔴Vulnerability Details

2
GHSA
GHSA-2cph-rvmj-cx7r: MapServer before 72022-05-24
OSV
CVE-2021-32062: MapServer before 72021-05-06

📋Vendor Advisories

1
Debian
CVE-2021-32062: mapserver - MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4...2021
CVE-2021-32062 — Path Traversal in Osgeo Mapserver | cvebase