vulnerability

Alpine Linux: CVE-2021-25631: Incomplete List of Disallowed Inputs

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
May 3, 2021
Added
Aug 22, 2024
Modified
Dec 5, 2025

Description

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.

Solution

alpine-linux-upgrade-libreoffice
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.