CVE-2020-7758: Path Traversal
Published Nov 2, 2020
·Updated
This affects versions of package browserless-chrome before 1.40.2-chrome-stable. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then sent back to a user. This can be escaped to fetch arbitrary files from a server.
Affected Software
1 affected component
browserless Chrome Node.js<1.40.2
Remediation
Event History
Nov 2, 2020
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-7758.
2
What is the severity of CVE-2020-7758?
The severity of CVE-2020-7758 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2020-7758?
Versions of package browserless-chrome before 1.40.2-chrome-stable are affected by CVE-2020-7758.
4
How can an attacker exploit CVE-2020-7758?
An attacker can exploit CVE-2020-7758 by escaping user input to fetch arbitrary files from a server.
5
How can CVE-2020-7758 be mitigated?
To mitigate CVE-2020-7758, update to version 1.40.2-chrome-stable or later of browserless-chrome.