« Volver al listado

CVE-2021-22028

Estado: ModificadaCrítica (9.1)—

In versions of Greenplum database prior to 5.28.6 and 6.14.0, greenplum database contains a file path traversal vulnerability leading to information disclosure from the file system. A malicious user can read/write information from the file system using this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-22028",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "gpfdist (Greenplum)",
          "versions": [
            {
              "status": "affected",
              "version": "gpfdist (Greenplum) versions 6.x.0  prior to 6.14.0 and 5.28.x prior to 5.28.6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-19T17:15:07.907",
  "references": [
    {
      "url": "https://github.com/greenplum-db/gpdb/security/advisories/GHSA-hqh5-m87w-57w2",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://github.com/greenplum-db/gpdb/security/advisories/GHSA-hqh5-m87w-57w2",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vmware.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In versions of Greenplum database prior to 5.28.6 and 6.14.0, greenplum database contains a file path traversal vulnerability leading to information disclosure from the file system. A malicious user can read/write information from the file system using this vulnerability."
    },
    {
      "lang": "es",
      "value": "En las versiones de Greenplum database anteriores a 5.28.6 y 6.14.0, la base de datos Greenplum contiene una vulnerabilidad de salto de ruta de archivos que conlleva a una divulgación de información del sistema de archivos. Un usuario malicioso puede leer/escribir información del sistema de archivos usando esta vulnerabilidad"
    }
  ],
  "lastModified": "2026-06-17T03:36:34.790",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:greenplum:greenplum:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53D7491E-7389-45F6-A047-39FB12012F73",
              "versionEndExcluding": "5.28.6"
            },
            {
              "criteria": "cpe:2.3:a:greenplum:greenplum:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D85B597-8AAC-45E6-ADB7-1DC91B67CB70",
              "versionEndExcluding": "6.14.0",
              "versionStartIncluding": "6.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}