SB2019020626 - Path traversal in curl (Alpine package)



SB2019020626 - Path traversal in curl (Alpine package)

Published: February 6, 2019

Security Bulletin ID SB2019020626
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Path traversal (CVE-ID: CVE-2018-3822)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with arbitrary identifiers and the attacker can register an account which an identifier that shares a suffix with a legitimate account. Both of those conditions must be true in order to exploit this flaw.


Remediation

Install update from vendor's website.