cbcvebase.
CVE-2021-3981
published 2022-03-10

CVE-2021-3981: A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read…

PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.32%
24.0th percentile
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiangrub2< grub2 2.06-8 (bookworm)grub2 2.06-8 (bookworm)
fedoraprojectfedora
gnugrub2<= 2.06
gnugrub2
gnugrub2>= 0 < 2.06-82.06-8
gnugrub2>= 0 < 2.06-82.06-8
gnugrub2>= 0 < 2.06-82.06-8
msrcazl3_grub2_2.06-14_on_azure_linux_3.0
msrcazl3_grub2_2.06-23_on_azure_linux_3.0
msrccbl2_grub2_2.06-5_on_cbl_mariner_2.0
msrccm1_grub2_2.06rc1-8_on_cbl_mariner_1.0
msrcgrub2-2.06-18.azl3.aarch64.rpm
msrcgrub2-2.06-18.azl3.x86_64.rpm
msrcgrub2-2.06-5.cm2.aarch64.rpm
msrcgrub2-2.06-5.cm2.x86_64.rpm
msrcgrub2-2.06rc1-8.cm1.aarch64.rpm
msrcgrub2-2.06rc1-8.cm1.x86_64.rpm
msrcgrub2-configuration-2.06-18.azl3.aarch64.rpm
msrcgrub2-configuration-2.06-18.azl3.x86_64.rpm
msrcgrub2-efi-2.06-18.azl3.aarch64.rpm
msrcgrub2-efi-2.06-18.azl3.x86_64.rpm
msrcgrub2-efi-2.06-5.cm2.aarch64.rpm
msrcgrub2-efi-2.06-5.cm2.x86_64.rpm
msrcgrub2-efi-2.06rc1-8.cm1.aarch64.rpm
msrcgrub2-efi-2.06rc1-8.cm1.x86_64.rpm

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.5MEDIUM
vendor_ubuntu4.5MEDIUM
vendor_debian3.3LOW
vendor_msrc3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.