PT-2020-15121 · Huawei · Gaussdb 200
Published
2020-02-17
·
Updated
2020-02-19
·
CVE-2020-1853
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GaussDB 200 version 6.5.1
Description
The issue is related to a path traversal vulnerability due to insufficient input path validation. An authenticated attacker can exploit this to traverse directories and download files to a specific directory, potentially causing information leakage.
Recommendations
For GaussDB 200 version 6.5.1, consider restricting access to sensitive directories and files as a temporary mitigation measure until a patch is available. Additionally, ensure that input path validation is properly implemented to prevent directory traversal attacks.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gaussdb 200