CVE-2021-24031

MEDIUM

Facebook Zstandard < 1.4.1 - Incorrect Default Permissions

Title source: rule
STIX 2.1

Description

In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 22.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-277 CWE-276
Status published
Products (1)
facebook/zstandard < 1.4.1
Published Mar 04, 2021
Tracked Since Feb 18, 2026