CVE-2021-43496 is a directory traversal vulnerability affecting the clustering_project clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated attacker to disclose critical secrets from anywhere on the system, significantly aiding in achieving remote code execution. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for detecting this Local File Inclusion, and it has a high FAUCET Risk Score of 97/100. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019-07-26CPE matchmatch criteria | cpe:2.3:a:clustering_project:clustering:2019-07-26:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.