Логотип exploitDog
bind:"CVE-2020-14352"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-14352"

Количество 8

Количество 8

redhat логотип

CVE-2020-14352

около 5 лет назад

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2020-14352

почти 5 лет назад

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.

CVSS3: 8
EPSS: Низкий
msrc логотип

CVE-2020-14352

почти 5 лет назад

CVSS3: 8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0277-1

больше 4 лет назад

Security update for librepo

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1289-1

почти 5 лет назад

Security update for librepo

EPSS: Низкий
github логотип

GHSA-2fcv-8cvq-hmxh

больше 3 лет назад

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5012

почти 5 лет назад

ELSA-2020-5012: librepo security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3658

почти 5 лет назад

ELSA-2020-3658: librepo security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-14352

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.

CVSS3: 8
4%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-14352

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.

CVSS3: 8
4%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 8
4%
Низкий
почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0277-1

Security update for librepo

4%
Низкий
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1289-1

Security update for librepo

4%
Низкий
почти 5 лет назад
github логотип
GHSA-2fcv-8cvq-hmxh

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.

4%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2020-5012

ELSA-2020-5012: librepo security update (MODERATE)

почти 5 лет назад
oracle-oval логотип
ELSA-2020-3658

ELSA-2020-3658: librepo security update (IMPORTANT)

почти 5 лет назад

Уязвимостей на страницу