5
CVSSv2

CVE-2021-32062

Published: 06/05/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

MapServer prior to 7.0.8, 7.1.x and 7.2.x prior to 7.2.3, 7.3.x and 7.4.x prior to 7.4.5, and 7.5.x and 7.6.x prior to 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

osgeo mapserver

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #988208 CVE-2021-32062 Package: src:mapserver; Maintainer for src:mapserver is Debian GIS Project <pkg-grass-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 7 May 2021 19:18:01 UTC Severity: grave Tags: security, upstream Found in versions mapserv ...