Vulnerability Description
The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashplan/log directory. This allows a user to manipulate symbolic links to escalate privileges, or show the contents of sensitive files that a regular user would not have access to.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Code42 | Code42 | < 6.8.4 |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/106452Third Party AdvisoryVDB Entry
- https://code42.com/r/support/CVE-2018-20131
- http://www.securityfocus.com/bid/106452Third Party AdvisoryVDB Entry
- https://code42.com/r/support/CVE-2018-20131
FAQ
What is CVE-2018-20131?
CVE-2018-20131 is a vulnerability with a CVSS score of 7.8 (HIGH). The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashplan/log directory. This allows a user to manipulate symbolic...
How severe is CVE-2018-20131?
CVE-2018-20131 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20131?
Check the references section above for vendor advisories and patch information. Affected products include: Code42 Code42, Linux Linux Kernel.