CVE-2020-11498: Path Traversal
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tundarwin.go or tunwindows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for user-level persistence or to bypass security controls. NOTE: the vendor states that this "requires a high degree of access and other preconditions that are tough to achieve."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11498?
CVE-2020-11498 is classified as a high severity vulnerability that allows privilege escalation.
How do I fix CVE-2020-11498?
To fix CVE-2020-11498, you should upgrade Slack Nebula to version 1.1.1 or later.
Who is affected by CVE-2020-11498?
Users of Slack Nebula version 1.1.0 and earlier are affected by CVE-2020-11498.
What type of vulnerability is CVE-2020-11498?
CVE-2020-11498 is a relative path vulnerability that can lead to arbitrary code execution.
Can CVE-2020-11498 be exploited locally?
Yes, CVE-2020-11498 can be exploited by low-privileged attackers locally to execute code.