SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1904

A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to…

MEDIUM 5.5EPSS 1.11%

Does this matter?

Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.

Description

A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS
1.11% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-23, CWE-22
Affected
whatsapp/whatsapp · whatsapp/whatsapp business
Source
cve-assign@fb.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.