ID:5022 - Exploit for Improper Certificate Validation in Backblaze - CVE-2020-8289

 
Main Vulnerability Database Exploits ID:5022 - Exploit for Improper Certificate Validation in Backblaze - CVE-2020-8289

ID:5022 - Exploit for Improper Certificate Validation in Backblaze - CVE-2020-8289

Published: January 11, 2021


Vulnerability identifier: #VU49189
Vulnerability risk: Medium
CVE-ID: CVE-2020-8289
CWE-ID: CWE-295
Exploitation vector: Remote access
Vulnerable software:
Backblaze

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to improper certificate validation in Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 in in `bztransmit` helper due to hardcoded whitelist of strings in URLs. A remote attacker can perform MitM attack, interfere with the update functionality.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Remediation

Install updates from vendor's website.