Improper Interaction Between Multiple Correctly-Behaving Entities in Go programming language - CVE-2020-29510

 

Improper Interaction Between Multiple Correctly-Behaving Entities in Go programming language - CVE-2020-29510

Published: July 26, 2023


Vulnerability identifier: #VU78680
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-29510
CWE-ID: CWE-435
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to incorrect preserving the semantics of directives during tokenization round-trips. A remote unauthenticated attacker can craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.


Affected software

Go programming language
ObjectScale
Dell PowerProtect Cyber Recovery
QRadar Suite

How to mitigate CVE-2020-29510

Install updates from vendor's website.

Go programming language - update to 1.15.1
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.18.0
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins