CVE-2018-20131

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/01/2019
Last modified:
03/10/2019

Description

The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashplan/log directory. This allows a user to manipulate symbolic links to escalate privileges, or show the contents of sensitive files that a regular user would not have access to.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:code42:code42:*:*:*:*:enterprise:*:*:* 6.8.4 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*