Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-24031

20
FAUCET Score

CVE-2021-24031 describes a vulnerability in the Zstandard command-line utility prior to version 1.4.1, where output files were initially created with default, potentially insecure permissions before being corrected at completion. This could allow unintended parties to read or write to these files, affecting Facebook Zstandard. With a CVSS score of 5.5 (Medium), this local vulnerability (AV:L) has low attack complexity (AC:L) and requires low privileges (PR:L), primarily impacting confidentiality (C:H) by exposing sensitive information. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating low current threat activity.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.4.1CPE matchmatch criteria
cpe:2.3:a:facebook:zstandard:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 90th percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (7)

capnprotovendor investigatingvia llm_extracted
gcpvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
kongvendor investigatingvia llm_extracted
openwrtvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted
redhatvendor investigatingvia redhat_api
Product: Red Hat Ceph Storage 3Fixed in: ceph

Vendor Advisories (7)

gcpllm-gcp-01a119d0ea3516faCRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
capnprotollm-capnproto-5feb06313b602a85HIGH

ctrlX Multiple Vulnerabilities

Apr 23, 2021
openwrtllm-openwrt-b814c0e383a6a281CRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
proxmoxllm-proxmox-202933dd58ce3ba3CRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
kongllm-kong-7933c1edf7557da9CRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
hanwhallm-hanwha-0b610f8bff10f748CRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
redhatCVE-2021-24031Low

zstd: adds read permissions to files while being compressed or uncompressed

Feb 11, 2021

References

bugs.debian.org / cgi-bin/bugreport.cgi
ExploitIssue TrackingMailing ListThird Party Advisory
github.com / facebook/zstd/issues/1630
ExploitIssue TrackingThird Party Advisory
facebook.com / security/advisories/cve-2021-24031
Vendor Advisory