VDB
ALINUX2-SA-2021%3A0040
ALINUX2-SA-2021%3A0040
PUBLISHED
CVSS 8.300000190734863 HIGH
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2021-33516: An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.
Risk Scores
CVSS 3.1
8.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | gupnp |
Timeline
- Jun 15, 2021 CVE Published
- Jun 15, 2021 CVE Updated