{ "schema_version": "1.4.0", "id": "GHSA-chrg-5pr2-gqgj", "modified": "2022-05-24T19:03:59Z", "published": "2022-05-24T19:03:59Z", "aliases": [ "CVE-2021-33805" ], "details": "In the reference implementation of FUSE before 2.9.8 and 3.x before 3.2.5, local attackers were able to specify the allow_other option even if forbidden in /etc/fuse.conf, leading to exposure of FUSE filesystems to other users. This issue only affects systems with SELinux active.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33805" }, { "type": "WEB", "url": "https://github.com/libfuse/libfuse/releases/tag/fuse-2.9.8" }, { "type": "WEB", "url": "https://github.com/libfuse/libfuse/releases/tag/fuse-3.2.5" } ], "database_specific": { "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-06-03T03:15:00Z" } }