Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-6354.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-6354
Upstream
Published
2021-04-19T22:15:12Z
Modified
2026-04-21T04:32:10.445846Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N CVSS Calculator
Summary
CVE-2021-20208 affecting package cifs-utils for versions less than 6.8-6
Details

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

References

Affected packages

Azure Linux:2 / cifs-utils

Package

Name
cifs-utils
Purl
pkg:rpm/azure-linux/cifs-utils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.8-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-6354.json"