Improper verification of cryptographic signature in Borg - CVE-2023-36811

 

Improper verification of cryptographic signature in Borg - CVE-2023-36811

Published: September 6, 2023


Vulnerability identifier: #VU80511
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36811
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to spoof backup archived.

The vulnerability exists due to improper verification of cryptographic signature. A remote user with write access to the repository can create fake archives that will appear to be valid. This can result in data loss.


Affected software

Borg
Fedora
borgbackup

How to mitigate CVE-2023-36811

Install updates from vendor's website.

Borg - update to 1.2.5
borgbackup - addressed in versions 1.1.18-2.el7, 1.1.18-2.el8, 1.2.6-1.el9, 1.2.6-1.fc37, 1.2.6-1.fc38, 1.2.6-1.fc39

External References

Related Security Bulletins