CVE-2021-24032 affects Zstandard versions 1.4.1 through 1.4.8, where an incomplete fix for a prior vulnerability allowed output files to be momentarily readable or writable by unauthorized parties due to default permissions before being restricted. This local vulnerability has a CVSS score of 4.7 (Medium), indicating high confidentiality impact with low privileges and high attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, with minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.1, < 1.4.9CPE matchmatch criteria | cpe:2.3:a:facebook:zstandard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-24032
Dec 10, 2024CVE-2021-24032
Jul 13, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021Beginning in v1.4.1 and prior to v1.4.9 due to an incomplete fix for CVE-2021-24031 the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.
Mar 9, 2021zstd: Race condition allows attacker to access world-readable destination file
Feb 11, 2021