CVE-2020-8289
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 4.66% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- backblaze/backblaze
- Source
- support@hackerone.com
References
- http://seclists.org/fulldisclosure/2020/Dec/57Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/58Mailing List, Third Party Advisory
- https://github.com/geffner/CVE-2020-8289/blob/master/README.mdExploit, Third Party Advisory
- https://hackerone.com/reports/818853Permissions Required
- https://www.backblaze.com/blog/backblaze-cloud-backup-release-7-0-1/Third Party Advisory
- https://youtu.be/W0THXbcX5V8Exploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/57Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/58Mailing List, Third Party Advisory
- https://github.com/geffner/CVE-2020-8289/blob/master/README.mdExploit, Third Party Advisory
- https://hackerone.com/reports/818853Permissions Required
- https://www.backblaze.com/blog/backblaze-cloud-backup-release-7-0-1/Third Party Advisory
- https://youtu.be/W0THXbcX5V8Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.