ZeroHour

CVE-2021-30855

CVSS 3.1
5.5 medium
EPSS
2%p83
Published
()
Modified
Description

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. An application may be able to access restricted files.

Vendors
apple
Products
ipados, iphone os, mac os x, macos, tvos, watchos
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.