Directory Traversal Affecting php81 package, versions <8.1.0_rc3-r0
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ALPINE319-PHP81-6110723
- published 8 Dec 2023
- disclosed 4 Oct 2021
Introduced: 4 Oct 2021
CVE-2021-21706 Open this link in a new tabHow to fix?
Upgrade Alpine:3.19
php81
to version 8.1.0_rc3-r0 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream php81
package and not the php81
package as distributed by Alpine
.
See How to fix?
for Alpine:3.19
relevant fixed versions and status.
In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.