Log

ASA-202107-69 edited at 27 Jul 2021 10:24:42
Impact
+ A single L7 deny intention could erroneously result in an allow action, leading to access restriction bypass. Furthermore, a malicious upstream could present an invalid certificate.
ASA-202107-69 created at 27 Jul 2021 10:21:49
ASA-202107-68 edited at 27 Jul 2021 10:21:09
Impact
+ A remote attacker could execute arbitrary code or disclose sensitive information through crafted web content. Apple is aware of a report that one of the issues may have been actively exploited.
ASA-202107-68 created at 27 Jul 2021 10:21:06
ASA-202107-67 edited at 27 Jul 2021 10:20:58
Impact
+ A remote attacker could execute arbitrary code or disclose sensitive information through crafted web content. Apple is aware of a report that one of the issues may have been actively exploited.
ASA-202107-67 created at 27 Jul 2021 10:19:44
AVG-2225 created at 27 Jul 2021 09:05:27
Packages
+ nextcloud
Issues
+ CVE-2021-32610
Status
+ Vulnerable
Severity
+ Medium
Affected
+ 22.0.0-2
Fixed
Ticket
Advisory qualified
+ Yes
References
Notes
AVG-2224 edited at 27 Jul 2021 09:01:34
Severity
- Unknown
+ Medium
CVE-2021-32610 edited at 27 Jul 2021 09:01:34
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Directory traversal
Description
+ In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
References
+ https://www.drupal.org/sa-core-2021-004
+ https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4f61ca26bf7d4
Notes
AVG-2224 created at 27 Jul 2021 08:58:19
Packages
+ drupal
Issues
+ CVE-2021-32610
Status
+ Not affected
Severity
+ Unknown
Affected
+ 9.2.0-1
Fixed
Ticket
Advisory qualified
+ No
References
Notes
CVE-2021-32610 created at 27 Jul 2021 08:58:19
AVG-2223 edited at 26 Jul 2021 21:15:28
Issues
+ CVE-2021-22885
CVE-2021-22902
CVE-2021-22904
- CVE-2021-31799