SB2018020928 - Input validation error in Borg
Published: February 9, 2018 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2017-15914)
The vulnerability allows a remote authenticated user to execute arbitrary code.
Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3.
Remediation
Install update from vendor's website.