cvelist/2020/7xxx/CVE-2020-7302.json

98 lines
3.3 KiB
JSON
Raw Normal View History

2020-01-21 14:01:28 +00:00
{
"CVE_data_meta": {
2020-08-12 21:46:29 -05:00
"ASSIGNER": "psirt@mcafee.com",
2020-01-21 14:01:28 +00:00
"ID": "CVE-2020-7302",
2020-08-12 21:46:29 -05:00
"STATE": "PUBLIC",
"TITLE": "DLP ePO extension - Unrestricted Upload of File with Dangerous Type"
2020-01-21 14:01:28 +00:00
},
2020-08-12 21:46:29 -05:00
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "DLP ePO extension",
"version": {
"version_data": [
{
"version_affected": "<",
"version_name": "11.3",
"version_value": "11.3.28"
},
{
"version_affected": "<",
"version_name": "11.4",
"version_value": "11.4.200"
},
{
"version_affected": "<",
"version_name": "11.5",
"version_value": "11.5.3"
}
]
}
}
]
},
"vendor_name": "McAfee"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
2020-01-21 14:01:28 +00:00
"description": {
"description_data": [
{
"lang": "eng",
2020-08-12 21:46:29 -05:00
"value": "Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-434 Unrestricted Upload of File with Dangerous Type"
}
]
2020-01-21 14:01:28 +00:00
}
]
2020-08-12 21:46:29 -05:00
},
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10326"
}
]
},
"source": {
"advisory": "SB10326",
"discovery": "EXTERNAL"
2020-01-21 14:01:28 +00:00
}
2020-08-12 21:46:29 -05:00
}