CVE-2021-24031 describes a vulnerability in the Zstandard command-line utility prior to version 1.4.1, where output files were initially created with default, potentially insecure permissions before being corrected at completion. This could allow unintended parties to read or write to these files, affecting Facebook Zstandard. With a CVSS score of 5.5 (Medium), this local vulnerability (AV:L) has low attack complexity (AC:L) and requires low privileges (PR:L), primarily impacting confidentiality (C:H) by exposing sensitive information. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating low current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.1CPE matchmatch criteria | cpe:2.3:a:facebook:zstandard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021zstd: adds read permissions to files while being compressed or uncompressed
Feb 11, 2021