CVE-2021-22571 describes a local file disclosure vulnerability affecting Google's SA360 Webquery to BigQuery Exporter. A local attacker could read other users' SA360 report files temporarily stored in the /tmp directory during the staging process before being loaded into BigQuery. Rated as Medium severity (CVSS 5.5), this vulnerability has a low attack complexity and requires local access (AV:L, AC:L, PR:L). The primary impact is high confidentiality compromise (C:H), allowing unauthorized access to sensitive report data. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. Users are advised to upgrade to version 1.0.3 or above to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.3CPE matchmatch criteria | cpe:2.3:a:google:sa360_webquery_to_bigquery_exporter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.