Medium severity5.3NVD Advisory· Published Oct 4, 2021· Updated Jun 17, 2026
CVE-2021-21706
CVE-2021-21706
Description
In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
23- osv-coords21 versionspkg:bitnami/libphppkg:bitnami/phppkg:bitnami/php-minpkg:rpm/opensuse/php7&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/php7&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/php7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/php7-test&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/php8&distro=openSUSE%20Tumbleweedpkg:rpm/suse/php74&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php74&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/php7&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP3pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/php7&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/php7&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/php7&distro=SUSE%20Manager%20Server%204.1
>= 7.3.0, < 7.3.31+ 20 more
- (no CPE)range: >= 7.3.0, < 7.3.31
- (no CPE)range: >= 7.3.0, < 7.3.31
- (no CPE)range: >= 7.3.0, < 7.3.31
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.24-1.1
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 8.0.11-1.1
- (no CPE)range: < 7.4.33-1.47.2
- (no CPE)range: < 7.4.33-1.47.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
- (no CPE)range: < 7.4.33-150200.3.46.2
Patches
Vulnerability mechanics
References
2- bugs.php.net/bug.phpnvdIssue TrackingPatchVendor Advisory
- security.netapp.com/advisory/ntap-20211029-0007/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.