PT-2020-12648 · Slack · Slack Nebula

Published

2020-04-02

·

Updated

2020-04-06

·

CVE-2020-11498

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slack Nebula versions 1.1.0 and earlier
Description The issue allows a low-privileged attacker to execute code in the context of the root user via tun darwin.go or tun windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, for example, for user-level persistence or to bypass security controls. The vendor notes that this requires a high degree of access and other preconditions that are tough to achieve.
Recommendations For versions 1.1.0 and earlier, update to a version that fixes the relative path vulnerability. As a temporary workaround, consider restricting access to tun darwin.go and tun windows.go to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11498

Affected Products

Slack Nebula