VDB
DEBIAN-CVE-2021-3139
DEBIAN-CVE-2021-3139
PUBLISHED
CVSS 8.100000381469727 HIGH
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | tcmu | 0, 0, 0 |
| Debian:13 | tcmu | 0, 0, 0 |
| Debian:12 | tcmu | 0, 0, 0 |
| Debian:14 | tcmu | 0, 0, 0 |
Timeline
- Jan 13, 2021 CVE Published
- Apr 28, 2026 CVE Updated