CVE-2021-22571

MEDIUM

sa360_webquery_to_bigquery_exporter < 1.0.3 - Unauthenticated Local File Read via Temporary Report Staging

Title source: llm
STIX 2.1

Description

A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.

References (3)

Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/google/sa360-webquery-bigquery/pull/15
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/google/sa360-webquery-bigquery/releases/tag/v1.0.3

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 9.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-275 CWE-276
Status published
Products (1)
google/sa360_webquery_to_bigquery_exporter < 1.0.3
Published Mar 18, 2022
Tracked Since Feb 18, 2026