Path traversal in AWStats - CVE-2020-29600
Published: December 7, 2020 / Updated: December 15, 2020
Vulnerability identifier: #VU49006
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-29600
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
AWStats
Arch Linux
Ubuntu
Fedora
awstats (Ubuntu package)
awstats
Arch Linux
Ubuntu
Fedora
awstats (Ubuntu package)
awstats
How to mitigate CVE-2020-29600
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
awstats (Ubuntu package) - addressed in versions 7.6+dfsg-2ubuntu0.18.04.1, 7.6+dfsg-2ubuntu0.20.04.1, 7.6+dfsg-2ubuntu0.20.10.1
awstats - update to 7.8-2.fc32
awstats - update to 7.8-2.fc32