SB2023090811 - Fedora EPEL 9 update for borgbackup
Published: September 8, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper verification of cryptographic signature (CVE-ID: CVE-2023-36811)
The vulnerability allows a remote user to spoof backup archived.
The vulnerability exists due to improper verification of cryptographic signature. A remote user with write access to the repository can create fake archives that will appear to be valid. This can result in data loss.
Remediation
Install update from vendor's website.