PT-2020-17212 · Awstats+3 · Awstats+3

Tomaž Šolc

·

Published

2020-12-07

·

Updated

2024-10-11

·

CVE-2020-29600

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AWStats versions prior to 7.8
Description The issue allows an absolute pathname to be accepted by the cgi-bin/awstats.pl endpoint, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. This is due to an incomplete fix for a previous issue.
Recommendations For AWStats versions prior to 7.8, consider restricting access to the cgi-bin/awstats.pl endpoint until a patch is available. As a temporary workaround, avoid using absolute pathnames in the config parameter of the cgi-bin/awstats.pl endpoint.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1396
ALT-PU-2024-13582
ALT-PU-2024-13745
CVE-2020-29600
DLA-2506-1
MGASA-2021-0024
USN-4953-1

Affected Products

Alt Linux
Awstats
Linuxmint
Ubuntu