
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-26299 affects ftp-srv, an open-source FTP server designed to be simple yet configurable, in versions before 4.4.0. The vulnerability allows clients of FTP servers utilizing ftp-srv hosted on Windows machines to escape the FTP user's defined root folder using standard FTP commands like CWD and UPDR (GitHub Advisory).
The vulnerability occurs when Windows separators exist within the path (''), where path.resolve leaves the upper pointers intact and allows the user to move beyond the root folder defined for that user. This path traversal vulnerability enables authenticated users to access directories outside their designated root folder (NVD). The issue has a CVSS v3.1 base score of 9.6 CRITICAL according to NVD, while GitHub rates it as MEDIUM with a score of 6.3 (NVD).
The vulnerability allows authenticated users to access files and directories outside their intended root directory on Windows systems. This could lead to unauthorized access to sensitive files and potential information disclosure on the hosting system (GitHub Advisory).
The vulnerability can be exploited by authenticated users using standard FTP commands. The attack requires low complexity and can be executed remotely with only low privileges required (NVD).
The issue was patched in version 4.4.0 with commit 457b859450a37cba10ff3c431eb4aa67771122e3. For users unable to upgrade, the only workaround is to host the FTP server on a non-Windows operating system (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."