Arbitrary file read and write via symlink traversal
Published Aug 16, 2021 · Updated Aug 3, 2024
Path traversal in bblfshd before commit 4265465b9b6fb5663c30ee43806126012066aad4 allows attackers to write arbitrary files via a crafted archive. The runtime untar routine validates each link's lexical path but fails to resolve previously created links, allowing chained symlinks to escape the extraction root. Exploitation requires control of an archive processed by bblfshd; writes use the daemon's permissions, while reading system files also requires access to extracted output.
Summary
What happened
Path traversal in bblfshd before commit 4265465b9b6fb5663c30ee43806126012066aad4 allows attackers to write arbitrary files via a crafted archive. The runtime untar routine validates each link's lexical path but fails to resolve previously created links, allowing chained symlinks to escape the extraction root. Exploitation requires control of an archive processed by bblfshd; writes use the daemon's permissions, while reading system files also requires access to extracted output.
The record
- CVE
- CVE-2021-32825
- Published
- Aug 16, 2021
- Updated
- Aug 3, 2024
- Vendor
- bblfsh
- Product
- bblfshd
- Classifications
- CWE-23, CWE-59, T1204.002
- Attack vector
- local
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 16, 2021CVE publishedPublication date reported by the CVE source.
- Aug 3, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=< 4265465b9b6fb5663c30ee43806126012066aad4
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- GitHub Security Lab nested-symlink proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo