SB2020122911 - MitM attack in Backblaze
Published: December 29, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Certificate Validation (CVE-ID: CVE-2020-8289)
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation in Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 in in `bztransmit` helper due to hardcoded whitelist of strings in URLs. A remote attacker can perform MitM attack, interfere with the update functionality.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.
Remediation
Install update from vendor's website.