ALT-PU-2017-3587-2
Closed vulnerabilities
Published: 2018-02-08
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-15914
Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3.
Severity: MEDIUM (6.5)Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
Severity: HIGH (8.8)Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2022-05-13
Modified: 2024-09-04
Modified: 2024-09-04
GHSA-8q8v-28rm-qw4w
Borg Improper Access Control vulnerability
Severity: HIGH (8.8)Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
- https://nvd.nist.gov/vuln/detail/CVE-2017-15914
- https://github.com/borgbackup/borg/commit/75854c1243b29ec5558be6fdefe365cd438abb4c
- https://github.com/borgbackup/borg
- https://github.com/pypa/advisory-database/tree/main/vulns/borgbackup/PYSEC-2018-105.yaml
- http://borgbackup.readthedocs.io/en/stable/changes.html#version-1-1-3-2017-11-27
