ID:5022 - Exploit for Improper Certificate Validation in Backblaze - CVE-2020-8289
Published: January 11, 2021
Backblaze
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation in Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 in in `bztransmit` helper due to hardcoded whitelist of strings in URLs. A remote attacker can perform MitM attack, interfere with the update functionality.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.