VDB
CVE-2021-3762
CVE-2021-3762
PUBLISHED
CVSS 7.800000190734863 HIGH
Path traversal in claircore
EPSS 4.81% · 91.3th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
4.81%
91.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | quay/claircore | 0, 0.5.0, 1.0.0 |
| n/a | quay/claircore | Affects v0.4.6 and higher, v0.5.3 and higher | Fixedin claircore v0.4.8, v0.5.5. |
| redhat | quay | 3.5.6 |
| redhat | clair | 0.4.6, 0.5.3 |
Timeline
- Mar 3, 2022 CVE Published
- Mar 4, 2022 EPSS Score
- Jun 15, 2022 EPSS Score
- Aug 7, 2022 EPSS Score
- Nov 18, 2022 EPSS Score
- Jan 30, 2023 CVE Updated
- Jan 31, 2023 EPSS Score
- Mar 2, 2023 EPSS Score
- Mar 10, 2023 EPSS Score
- Jun 13, 2023 EPSS Score
- Aug 4, 2023 EPSS Score
- Oct 9, 2023 EPSS Score
References
- https://github.com/quay/claircore/pull/478 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2000795 url
- https://vulmon.com/exploitdetails?qidtp=maillist_oss_security&qid=d19fce9ede06e13dfb5630ece7f14f83 url
- https://github.com/quay/clair/pull/1380 patch
- https://github.com/quay/clair/pull/1379 patch
- https://github.com/quay/claircore/commit/691f2023a1720a0579e688b69a2f4bfe1f4b7821 patch
- https://nvd.nist.gov/vuln/detail/CVE-2021-3762 advisory
- https://github.com/quay/claircore/commit/dff671c665141f126c072de8a744855d4916c9c7 url
- https://github.com/quay/claircore/commit/ed5f52aec1c82746725e9cc23e98316eab8be25a url
- https://github.com/quay/claircore package
- https://github.com/quay/claircore/commits/v0.4.8 url
- https://github.com/quay/claircore/commits/v0.5.5 url
- https://github.com/quay/claircore/commits/v1.1.0 url
- https://pkg.go.dev/vuln/GO-2022-0346 url