Executive brief
rdiffweb is an open-source backup web interface for the rdiff-backup utility, used to manage and restore file backups remotely. The vulnerability involves business logic errors that could allow an authenticated user with high privileges to perform unauthorized actions or manipulate backup operations, though the exact impact is limited.
Technical details
The vulnerability is a business logic error in rdiffweb versions prior to 2.5.5. The attack requires administrative privileges and user interaction (CVSS v3 vector: AV:P/AC:L/PR:H/UI:R), meaning an authenticated high-privileged user must perform a specific action. The patch, released in version 2.5.5, addresses the logic flaw through a commit that adds notification functionality for SSH key changes. The vulnerability affects all versions from 0.x through 2.5.4.
Affected products
- rdiffweb contributors rdiffweb before 2.5.5
Timeline
- 2022-12-27: disclosed
- 2022-12-27: patched: Fixed in version 2.5.5