Improper Interaction Between Multiple Correctly-Behaving Entities in Go programming language - CVE-2020-29510
Published: July 26, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to incorrect preserving the semantics of directives during tokenization round-trips. A remote unauthenticated attacker can craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
Affected software
ObjectScale
Dell PowerProtect Cyber Recovery
QRadar Suite
How to mitigate CVE-2020-29510
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.18.0
Dell PowerProtect Cyber Recovery - update to 19.14.0.1