VulnerabilityModified
CVE-2020-14318
An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.
MEDIUM 4.3EPSS 1.54%
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266, CWE-269
- Affected
- samba/samba · redhat/storage · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1892631Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://security.gentoo.org/glsa/202012-24Third Party Advisory
- https://www.samba.org/samba/security/CVE-2020-14318.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1892631Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://security.gentoo.org/glsa/202012-24Third Party Advisory
- https://www.samba.org/samba/security/CVE-2020-14318.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.