Back to search
CVE-2015-4082
Published: Aug 18, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted repository to obtain potentially sensitive information by changing the manifest type byte of the repository to "unencrypted / without key file".
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/jborg/attic/issues/271
x_refsource_CONFIRM
[oss-security] 20150531 Re: CVE request for attic : encrypted backups attack
mailing-list
x_refsource_MLIST
74821
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now