Описание
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in bztransmit helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- ExploitThird Party Advisory
- Permissions Required
- Third Party Advisory
- ExploitThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- ExploitThird Party Advisory
- Permissions Required
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.0.1.433 (исключая)Версия до 7.0.1.434 (исключая)
Одно из
cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:windows:*:*
cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:macos:*:*
EPSS
Процентиль: 95%
0.20543
Средний
7.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-295
CWE-295
Связанные уязвимости
github
больше 3 лет назад
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.
EPSS
Процентиль: 95%
0.20543
Средний
7.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-295
CWE-295