SB2020122911 - MitM attack in Backblaze



SB2020122911 - MitM attack in Backblaze

Published: December 29, 2020

Security Bulletin ID SB2020122911
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Certificate Validation (CVE-ID: CVE-2020-8289)

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to improper certificate validation in Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 in in `bztransmit` helper due to hardcoded whitelist of strings in URLs. A remote attacker can perform MitM attack, interfere with the update functionality.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Remediation

Install update from vendor's website.