CVE-2021-32062: Path Traversal
MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MSMAPNOPATH and MSMAPPATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32062?
CVE-2021-32062 is a vulnerability in MapServer that allows unauthorized loading of mapfiles.
What is the severity of CVE-2021-32062?
CVE-2021-32062 has a severity rating of 5.3 (medium).
How does CVE-2021-32062 affect MapServer?
CVE-2021-32062 affects MapServer versions before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3.
What is the impact of CVE-2021-32062?
The impact of CVE-2021-32062 is that it allows unauthorized users to load mapfiles, potentially exposing sensitive information.
How can I fix CVE-2021-32062?
To fix CVE-2021-32062, upgrade to MapServer version 7.0.8, 7.2.3, 7.4.5, 7.6.3, or later.