{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Critical"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "directory traversal when scanning crafted container image layer allows for arbitrary file write",
    "tracking": {
      "current_release_date": "2026-08-11T14:59:31+00:00",
      "generator": {
        "date": "2026-08-11T14:59:31+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-3762",
      "initial_release_date": "2021-09-28T12:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:59:31+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Quay v3.5.0",
            "product": {
              "name": "Red Hat Quay v3.5.0",
              "product_id": "quay-3.5",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:quay:3"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Quay v3.6.0",
            "product": {
              "name": "Red Hat Quay v3.6.0",
              "product_id": "quay-3.6",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:quay:3"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Quay v3.15.0",
            "product": {
              "name": "Red Hat Quay v3.15.0",
              "product_id": "quay-3::el8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:quay:3::el8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "quay-clair-container-v3.5.7",
            "product": {
              "name": "quay-clair-container-v3.5.7",
              "product_id": "quay-clair-container-v3.5.7-0:8",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/quay-clair-container-v3.5.7@8?epoch=0"
              }
            }
          },
          {
            "category": "product_version",
            "name": "quay/clair-rhel8",
            "product": {
              "name": "quay/clair-rhel8",
              "product_id": "quay/clair-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/clair-rhel8?repository_url=registry.redhat.io/quay/clair-rhel8"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "quay-clair-container-v3.5.7-0:8 as a component of Red Hat Quay v3.15.0",
          "product_id": "quay-3::el8:quay-clair-container-v3.5.7-0:8"
        },
        "product_reference": "quay-clair-container-v3.5.7-0:8",
        "relates_to_product_reference": "quay-3::el8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "quay/clair-rhel8 as a component of Red Hat Quay v3.5.0",
          "product_id": "quay-3.5:quay/clair-rhel8"
        },
        "product_reference": "quay/clair-rhel8",
        "relates_to_product_reference": "quay-3.5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "quay/clair-rhel8 as a component of Red Hat Quay v3.6.0",
          "product_id": "quay-3.6:quay/clair-rhel8"
        },
        "product_reference": "quay/clair-rhel8",
        "relates_to_product_reference": "quay-3.6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-3762",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "discovery_date": "2021-09-02T00:00:00+00:00",
      "notes": [
        {
          "category": "other",
          "text": "Only a single version of Red Hat Quay, 3.5.6 is affected by this vulnerability. All previous released versions of Red Hat Quay are not affected by this vulnerability.\n\nThe overall vulnerability is rated as Critical for the ClairCore engine, but only rated Important for the Red Hat Quay product. In Red Hat Quay, Clair runs as the 'nobody' user in an unprivileged container, limiting the impact to modification of non-sensitives files in that container.\n\nRed Hat Advanced Cluster Security is not affected by this vulnerability.\n\nQuay.io is not affected by this vulnerability.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "quay-3::el8:quay-clair-container-v3.5.7-0:8"
        ],
        "known_affected": [
          "quay-3.5:quay/clair-rhel8",
          "quay-3.6:quay/clair-rhel8"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-3762"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3762"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3762"
        }
      ],
      "remediations": [
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "quay-3.5:quay/clair-rhel8",
            "quay-3.6:quay/clair-rhel8"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2021-09-28T21:19:17+00:00",
          "details": "Apply advisory RHSA-2021:3665 as per vendors instructions.",
          "product_ids": [
            "quay-3::el8:quay-clair-container-v3.5.7-0:8"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:3665"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
          "product_ids": [
            "quay-3.5:quay/clair-rhel8",
            "quay-3.6:quay/clair-rhel8"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "baseScore": 7.5,
            "baseSeverity": "HIGH"
          },
          "products": [
            "quay-3.5:quay/clair-rhel8",
            "quay-3.6:quay/clair-rhel8"
          ]
        },
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL"
          },
          "products": [
            "quay-3::el8:quay-clair-container-v3.5.7-0:8"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "quay-3.5:quay/clair-rhel8",
            "quay-3.6:quay/clair-rhel8"
          ]
        },
        {
          "category": "impact",
          "details": "Critical",
          "product_ids": [
            "quay-3::el8:quay-clair-container-v3.5.7-0:8"
          ]
        }
      ],
      "title": "directory traversal when scanning crafted container image layer allows for arbitrary file write"
    }
  ]
}