CVE Database
/

CVE-2020-8289

Back to search

CVE-2020-8289

Published: Dec 27, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.

VendorProductVersions

n/a

Backblaze

affected
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now