CVE-2021-24031
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.
- Facebook Zstandard
- < 1.4.1
- Fix
- Available
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.4% (35th percentile)
- Weakness
- CWE-277, CWE-276
- NVD status
- Modified
- Published
- 2021-03-04
CVE-2021-24031 at NVD
No indexed exploits for CVE-2021-24031 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-24031 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.