First published: Sun Feb 25 2018(Updated: )
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/awstats | <=7.6+dfsg-2<=7.2+dfsg-1+deb8u1<=7.6+dfsg-1+deb9u1 | |
Awstats Awstats | <=7.7 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29600 is a vulnerability in AWStats that allows an absolute pathname to be accepted instead of the intended format.
The severity of CVE-2020-29600 is critical with a CVSS severity score of 9.8.
CVE-2020-29600 allows an absolute pathname to be accepted in the 'config' parameter of cgi-bin/awstats.pl file, which can lead to unauthorized access of files.
AWStats versions up to and including 7.7 are affected by CVE-2020-29600.
At the moment, there is no known fix available for CVE-2020-29600. It is recommended to update to a patched version of AWStats when it becomes available.