CVE-2021-20208: Medium severity cifs utils vulnerability
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.
Other sources
A flaw was found in cifs-utils. From inside a container, cifs.upcall can read the credential caches for users on the host system potentially allowing hijacking of credentials.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2021-20208.
What is the severity of CVE-2021-20208?
The severity of CVE-2021-20208 is medium with a severity value of 6.1.
Which software versions are affected by CVE-2021-20208?
Versions of cifs-utils before 6.13 are affected by this vulnerability.
How can this vulnerability be fixed?
To fix this vulnerability, update cifs-utils to version 6.13 or later.
What is the highest threat from CVE-2021-20208?
The highest threat from CVE-2021-20208 is to data confidentiality and integrity.