Path traversal in go-slug - CVE-2020-29529
Published: December 3, 2020 / Updated: December 7, 2020
Vulnerability identifier: #VU48809
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-29529
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when handling files and symlinks in Unpack function. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
go-slug
IBM Cloud Pak for Watson AIOps
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak for Watson AIOps
Red Hat Advanced Cluster Management for Kubernetes
How to mitigate CVE-2020-29529
Install update from vendor's website.
go-slug - update to 0.5.0
IBM Cloud Pak for Watson AIOps - update to 3.5.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.2
IBM Cloud Pak for Watson AIOps - update to 3.5.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.2