CVE-2021-29101: ArcGIS GeoEvent Server has a Directory Traversal security vulnerability.
Published May 5, 2021
·Updated
ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.
Affected Software
2 affected components
Esri Arcgis Geoevent Server<=10.8.1
ArcGIS GeoEvent Server<=10.8.1
Remediation
Information
Esri has released a patch to address this issue.
Event History
May 5, 2021
CVE Published
via MITRE·06:21 PM
Data Sourced
via MITRE·06:21 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-29101?
CVE-2021-29101 is rated with a medium severity level due to its potential for unauthorized file access.
2
How do I fix CVE-2021-29101?
To fix CVE-2021-29101, apply the security patch provided by Esri for ArcGIS GeoEvent Server version 10.8.1 and below.
3
Who is affected by CVE-2021-29101?
CVE-2021-29101 affects all versions of ArcGIS GeoEvent Server up to and including 10.8.1.
4
What can an attacker do with CVE-2021-29101?
An attacker exploiting CVE-2021-29101 can read arbitrary files on the system using directory traversal techniques.
5
Is authentication required to exploit CVE-2021-29101?
No, CVE-2021-29101 can be exploited by unauthenticated remote attackers.