VDB

ALINUX2-SA-2021%3A0040

ALINUX2-SA-2021%3A0040 PUBLISHED CVSS 8.300000190734863 HIGH

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2021-33516: An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

Risk Scores

CVSS 3.1
8.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L

Affected Products

VendorProductVersions
Alibaba Cloudgupnp

Timeline

  • Jun 15, 2021 CVE Published
  • Jun 15, 2021 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›