Filtered by vendor Backblaze
Subscribe
Total
4 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-23653 | 1 Backblaze | 1 B2 Command Line Tool | 2024-11-21 | 1.9 LOW | 4.7 MEDIUM |
|
B2 Command Line Tool is the official command line tool for the backblaze cloud storage service. Linux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. The command line tool saves API keys (and bucket name-to-id mapping) in a local database file (`$XDG_CONFIG_HOME/b2/account_info`, `~/.b2_account_info` or a user-de ...
Show More |
|||||
| CVE-2022-23651 | 1 Backblaze | 1 B2 Python Software Development Kit | 2024-11-21 | 1.9 LOW | 4.7 MEDIUM |
|
b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK version 1.14.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. SDK users of the SqliteAccountInfo format are vulnerable while users of the InMemoryAccountInfo format are safe. The SqliteAccountInfo saves API keys (and bucket name-to-id mapping) in a local da ...
Show More |
|||||
| CVE-2020-8290 | 1 Backblaze | 1 Backblaze | 2024-11-21 | 4.6 MEDIUM | 7.8 HIGH |
|
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.
|
|||||
| CVE-2020-8289 | 1 Backblaze | 1 Backblaze | 2024-11-21 | 9.3 HIGH | 7.8 HIGH |
|
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.
|
|||||