{"id":"CVE-2021-47688","details":"In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be truncated in the OpenFileDescriptor action before the VerifyCanWrite action is performed.","aliases":["GHSA-3f8r-9483-pfxj"],"modified":"2026-07-09T03:25:23.769520Z","published":"2025-06-23T20:15:26.957Z","references":[{"type":"WEB","url":"https://github.com/WhiteBeamSec/WhiteBeam/security/policy"},{"type":"ADVISORY","url":"https://github.com/WhiteBeamSec/WhiteBeam/security/advisories/GHSA-3f8r-9483-pfxj"},{"type":"FIX","url":"https://github.com/WhiteBeamSec/WhiteBeam/pull/22"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/whitebeamsec/whitebeam","events":[{"introduced":"797e00ea9fdd3341f14af0edb39d736480858c24"},{"fixed":"d68a8e78a000ed52e68e9c33a764ce87af8495d8"},{"introduced":"0"},{"fixed":"e73b37ff9eaa6166f8ba9c115c5996ab687428d6"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0.2.0"},{"fixed":"0.2.1"},{"introduced":"0"},{"fixed":"0.2.2"}]}}],"versions":["v0.2.1","v0.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47688.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L"}]}