---
title: "CVE-2021-21707"
canonical: "https://kb.cynergy.app/space/MD/927629342/CVE-2021-21707"
format: markdown
---
**Description**

Certain versions of [Debian Linux](https://cve.report/software/debian/debian_linux) from [Debian](https://cve.report/vendor/debian) contain the following vulnerability:

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

**Published On**

02/27/2022

**Updated On**

10/07/2022

**Trending**

FALSE

**CWE**

<u>[CWE-159](http://cwe.mitre.org/data/definitions/159.html)</u>

**Exploit**

[https://bugs.php.net/bug.php?id=79971](https://bugs.php.net/bug.php?id=79971) 

 

**Mitigation:**

![image](media://8465f170-6188-4e76-89b3-1449c6bed72f)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- [150480](https://cve.report/qid/150480) Improper Handling of XML Functions in PHP (CVE-2021-21707)
- [179085](https://cve.report/qid/179085) Debian Security Update for php7.4 (DSA 5082-1)
- [198686](https://cve.report/qid/198686) Ubuntu Security Notification for Hypertext Preprocessor (PHP) Vulnerabilities (USN-5300-2)
- [198690](https://cve.report/qid/198690) Ubuntu Security Notification for Hypertext Preprocessor (PHP) Vulnerabilities (USN-5300-3)
- [240535](https://cve.report/qid/240535) Red Hat Update for rh-php73-php (RHSA-2022:5491)
- [282077](https://cve.report/qid/282077) Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2021-88ba46f2b2)
- [282078](https://cve.report/qid/282078) Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2021-c8043fa05f)
- [282149](https://cve.report/qid/282149) Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2021-06795380db)
- [501146](https://cve.report/qid/501146) Alpine Linux Security Update for php7
- [501665](https://cve.report/qid/501665) Alpine Linux Security Update for php7
- [501668](https://cve.report/qid/501668) Alpine Linux Security Update for php8
- [502330](https://cve.report/qid/502330) Alpine Linux Security Update for php81
- [671646](https://cve.report/qid/671646) EulerOS Security Update for Hypertext Preprocessor (PHP) (EulerOS-SA-2022-1755)
- [751448](https://cve.report/qid/751448) SUSE Enterprise Linux Security Update for php74 (SUSE-SU-2021:3927-1)
- [751467](https://cve.report/qid/751467) OpenSUSE Security Update for php7 (openSUSE-SU-2021:3943-1)
- [751513](https://cve.report/qid/751513) OpenSUSE Security Update for php7 (openSUSE-SU-2021:1570-1)
- [751763](https://cve.report/qid/751763) SUSE Enterprise Linux Security Update for php72 (SUSE-SU-2022:0577-1)
- [751772](https://cve.report/qid/751772) SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:0679-1)
- [751779](https://cve.report/qid/751779) OpenSUSE Security Update for php7 (openSUSE-SU-2022:0679-1)
- [901256](https://cve.report/qid/901256) Common Base Linux Mariner (CBL-Mariner) Security Update for Hypertext Preprocessor (PHP) (7328)

**References**

|  |  |  |
| --- | --- | --- |
| CVE-2021-21707 PHP Vulnerability in NetApp Products | NetApp Product Security | [http://security.netapp.com](http://security.netapp.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Debian -- Security Information -- DSA-5082-1 php7.4 | [http://www.debian.org](http://www.debian.org)   
<span style="color: #ffffff">**Depreciated Link**</span>  
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| [R1] [Tenable.sc](http://Tenable.sc) 5.21.0 Fixes Multiple Third-Party Vulnerabilities - Security Advisory | Tenable® | [http://www.tenable.com](http://www.tenable.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| PHP :: Sec Bug #79971 :: special character is breaking the path in xml function | [http://bugs.php.net](http://bugs.php.net)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |

![image](media://bf3da6ba-ada2-4b38-b960-301ac96d73a6)