CVE-2020-27304
published 2021-10-21CVE-2020-27304: The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.14%
86.4th percentile
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| civetweb_project | civetweb | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| civetweb_project | civetweb | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| civetweb_project | civetweb | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| civetweb_project | civetweb | >= 1.8 < unspecified | unspecified |
| civetweb_project | civetweb | >= 1.8 < 1.15 | 1.15 |
| debian | civetweb | < civetweb 1.15+dfsg-1 (bookworm) | civetweb 1.15+dfsg-1 (bookworm) |
| msrc | azl3_ceph_16.2.10-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.1-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_ceph_16.2.10-7_on_cbl_mariner_2.0 | — | — |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | 1.0.1.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wphm-mh7c-38cf: The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file u
ghsa_unreviewed·2022-05-24
CVE-2020-27304 [CRITICAL] CWE-22 GHSA-wphm-mh7c-38cf: The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file u
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
OSV
CVE-2020-27304: The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file u
osv·2021-10-21·CVSS 9.8
CVE-2020-27304 [CRITICAL] CVE-2020-27304: The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file u
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
CISA ICS
Siemens SCALANCE LPE9403 Third-Party Vulnerabilities
cisa_ics·2022-06-16·CVSS 9.8
[CRITICAL] Siemens SCALANCE LPE9403 Third-Party Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE LPE9403 Third-Party Vulnerabilities
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely, low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE LPE9403
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause crashes and unrestricted file access, impacting the product’s confidentiality, integrity, and availability.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of SCALANCE LPE9403 (Local Processing
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Red Hat
civetweb: directory traversal when using the built-in example HTTP form-based file upload mechanism via the mg_handle_form_request API
vendor_redhat·2021-10-18·CVSS 9.8
CVE-2020-27304 [CRITICAL] CWE-22 civetweb: directory traversal when using the built-in example HTTP form-based file upload mechanism via the mg_handle_form_request API
civetweb: directory traversal when using the built-in example HTTP form-based file upload mechanism via the mg_handle_form_request API
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
A remote code execution vulnerability was found in CivetWeb (embeddable web server/library). Due to a directory traversal issue, an attacker is able to add or overwrite files that are subsequently executed which lead to impact to confidentiality, integrity, and availability of the application.
Sta
Microsoft
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows when using the built-in HTTP form-based file upload mechanism via the mg_handle_form_request API.
vendor_msrc·2021-10-12·CVSS 9.8
CVE-2020-27304 [CRITICAL] CWE-22 The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows when using the built-in HTTP form-based file upload mechanism via the mg_handle_form_request API.
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows when using the built-in HTTP form-based file upload mechanism via the mg_handle_form_request API. Web applications that use the file upload form handler and use parts of the user-controlled filename in the output path are susceptible to directory traversal
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which i
Debian
CVE-2020-27304: civetweb - The CivetWeb web library does not validate uploaded filepaths when running on an...
vendor_debian·2020·CVSS 9.8
CVE-2020-27304 [CRITICAL] CVE-2020-27304: civetweb - The CivetWeb web library does not validate uploaded filepaths when running on an...
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
Scope: local
bookworm: resolved (fixed in 1.15+dfsg-1)
bullseye: open
forky: resolved (fixed in 1.15+dfsg-1)
sid: resolved (fixed in 1.15+dfsg-1)
trixie: resolved (fixed in 1.15+dfsg-1)
No detection rules found.
No public exploits indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://groups.google.com/g/civetweb/c/yPBxNXdGgJQhttps://jfrog.com/blog/cve-2020-27304-rce-via-directory-traversal-in-civetweb-http-server/https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://groups.google.com/g/civetweb/c/yPBxNXdGgJQhttps://jfrog.com/blog/cve-2020-27304-rce-via-directory-traversal-in-civetweb-http-server/
2021-10-21
Published