Skip to content

Full path disclosure in restore backup script

Moderate
piRGoif published GHSA-88fq-r22m-64q2 Sep 18, 2020

Package

No package listed

Affected versions

<2.7.1, < 3.0.0

Patched versions

2.7.1, 3.0.0

Description

Impact

When called with an invalid token, the restore backup script displays the full path of the token and doesn't escape token name properly.

Patches

  • 2.7.1 : packages community, essential, professional
  • 3.0.0 : to be published

Credits

Many thanks to TW/CERT for his report !

References

Combodo ref N°2988
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12777

For more information

If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com

Severity

Moderate

CVE ID

CVE-2020-12777

Weaknesses

No CWEs