CVE-2021-20208

EUVD-2021-7651
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
sambacifs-utils
4.0 ≤
𝑥
< 6.13
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cifs-utils
bookworm
2:7.0-2
fixed
bullseye
2:6.11-3.1+deb11u2
fixed
bullseye (security)
2:6.11-3.1+deb11u1
fixed
buster
no-dsa
sid
2:7.0-2.1
fixed
stretch
no-dsa
trixie
2:7.0-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cifs-utils
bionic
Fixed 2:6.8-1ubuntu1.2
released
focal
Fixed 2:6.9-1ubuntu0.2
released
groovy
ignored
hirsute
ignored
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
needed
xenial
needed