Input validation error in Borg - CVE-2017-15914

 

Input validation error in Borg - CVE-2017-15914

Published: February 9, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37555
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15914
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to execute arbitrary code.

Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3.


Affected software

Borg
Fedora
borgbackup

How to mitigate CVE-2017-15914

Install update from vendor's website.

Borg - update to 1.1.3
borgbackup - addressed in versions 1.1.3-1.el7, 1.1.3-1.fc26, 1.1.3-1.fc27

External References

Related Security Bulletins