9.3

CVE-2020-8289

Exploit
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BackblazeBackblaze SwPlatformwindows Version < 7.0.1.433
BackblazeBackblaze SwPlatformmacos Version < 7.0.1.434
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.66% 0.906
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

http://seclists.org/fulldisclosure/2020/Dec/57
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2020/Dec/58
Third Party Advisory
Mailing List
https://github.com/geffner/CVE-2020-8289/blob/master/README.md
Third Party Advisory
Exploit
https://hackerone.com/reports/818853
Permissions Required
https://www.backblaze.com/blog/backblaze-cloud-backup-release-7-0-1/
Third Party Advisory
https://youtu.be/W0THXbcX5V8
Third Party Advisory
Exploit