Vulnerability Description
Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live query is currently ongoing. We believe the impact of this vulnerability to be low given the requirement that the actor has a valid node key. There is no information disclosure, privilege escalation, or code execution. The issue is fixed in Fleet 3.7.0.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fleetdm | Fleet | < 3.7.0 |
Related Weaknesses (CWE)
References
- https://github.com/fleetdm/fleet/commit/f68f4238e83b45b2164e4ed05df14af0f06eaf40PatchThird Party Advisory
- https://github.com/fleetdm/fleet/security/advisories/GHSA-xwh8-9p3f-3x45Third Party Advisory
- https://www.npmjs.com/package/fleetctlProductThird Party Advisory
- https://github.com/fleetdm/fleet/commit/f68f4238e83b45b2164e4ed05df14af0f06eaf40PatchThird Party Advisory
- https://github.com/fleetdm/fleet/security/advisories/GHSA-xwh8-9p3f-3x45Third Party Advisory
- https://www.npmjs.com/package/fleetctlProductThird Party Advisory
FAQ
What is CVE-2021-21296?
CVE-2021-21296 is a vulnerability with a CVSS score of 2.7 (LOW). Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in den...
How severe is CVE-2021-21296?
CVE-2021-21296 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21296?
Check the references section above for vendor advisories and patch information. Affected products include: Fleetdm Fleet.