PT-2020-15121 · Huawei · Gaussdb 200

Published

2020-02-17

·

Updated

2020-02-19

·

CVE-2020-1853

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GaussDB 200 version 6.5.1
Description The issue is related to a path traversal vulnerability due to insufficient input path validation. An authenticated attacker can exploit this to traverse directories and download files to a specific directory, potentially causing information leakage.
Recommendations For GaussDB 200 version 6.5.1, consider restricting access to sensitive directories and files as a temporary mitigation measure until a patch is available. Additionally, ensure that input path validation is properly implemented to prevent directory traversal attacks.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1853

Affected Products

Gaussdb 200