{"id":"GHSA-8q8v-28rm-qw4w","summary":"Borg Improper Access Control vulnerability","details":"Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3.","aliases":["CVE-2017-15914","PYSEC-2018-105"],"modified":"2024-09-04T20:33:12.596888Z","published":"2022-05-13T01:44:03Z","database_specific":{"severity":"HIGH","cwe_ids":["CWE-284"],"github_reviewed_at":"2024-04-29T14:26:06Z","github_reviewed":true,"nvd_published_at":"2018-02-08T23:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15914"},{"type":"WEB","url":"https://github.com/borgbackup/borg/commit/75854c1243b29ec5558be6fdefe365cd438abb4c"},{"type":"PACKAGE","url":"https://github.com/borgbackup/borg"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/borgbackup/PYSEC-2018-105.yaml"},{"type":"WEB","url":"http://borgbackup.readthedocs.io/en/stable/changes.html#version-1-1-3-2017-11-27"}],"affected":[{"package":{"name":"borgbackup","ecosystem":"PyPI","purl":"pkg:pypi/borgbackup"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0b1"},{"fixed":"1.1.3"}]}],"versions":["1.1.0","1.1.0b1","1.1.0b2","1.1.0b3","1.1.0b4","1.1.0b5","1.1.0b6","1.1.0rc1","1.1.0rc2","1.1.0rc3","1.1.0rc4","1.1.1","1.1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-8q8v-28rm-qw4w/GHSA-8q8v-28rm-qw4w.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}