{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-02T01:34:13.958","vulnerabilities":[{"cve":{"id":"CVE-2021-21269","sourceIdentifier":"security-advisories@github.com","published":"2021-01-20T18:15:12.627","lastModified":"2024-11-21T05:47:53.877","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Keymaker is a Mastodon Community Finder based Matrix Community serverlist page Server. In Keymaker before version 0.2.0, the assets endpoint did not check for the extension. The rust `join` method without checking user input might have made it abe to do a Path Traversal attack causing to read more files than allowed. This is fixed in version 0.2.0."},{"lang":"es","value":"Keymaker es un servidor de páginas de lista de servidores Matrix Community basado en Mastodon Community Finder.&#xa0;En Keymaker anterior a versión 0.2.0, el endpoint de activos no comprobaba la extensión.&#xa0;El método de rust \"join\" sin verificar la entrada del usuario podría haber hecho que sea posible realizar un ataque de Salto de Ruta causando la lectura de más archivos de los permitidos.&#xa0;Esto es corregido en la versión 0.2.0"}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:keymaker_project:keymaker:*:*:*:*:*:*:*:*","versionEndExcluding":"0.2.0","matchCriteriaId":"DB094811-E3DB-42F0-B93C-9A852D9B92AC"}]}]}],"references":[{"url":"https://github.com/keymaker-mx/keymaker/commit/63f3012b390ff1519a84100df9e5dff5058bb926","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/keymaker-mx/keymaker/security/advisories/GHSA-pg25-xfcf-vjvm","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://github.com/keymaker-mx/keymaker/commit/63f3012b390ff1519a84100df9e5dff5058bb926","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/keymaker-mx/keymaker/security/advisories/GHSA-pg25-xfcf-vjvm","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}