VYPR

Borg

by Borgbackup

Source repositories

CVEs (5)

  • CVE-2017-15914HigFeb 8, 2018
    risk 0.50cvss 8.8epss 0.02

    Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3.

  • CVE-2016-10100MedJan 2, 2017
    risk 0.35cvss 5.3epss 0.01

    Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery, potentially allowing an attacker to overwrite an archive.

  • CVE-2016-10099MedJan 2, 2017
    risk 0.35cvss 5.3epss 0.01

    Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of archives), potentially allowing an attacker to spoof the list of archives.

  • CVE-2023-26265MedFeb 21, 2023
    risk 0.34cvss 5.3epss 0.01

    The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preprocess_page in the file template.php does not properly sanitize incoming path arguments before using them.

  • CVE-2023-36811MedAug 30, 2023
    risk 0.24cvss 4.7epss 0.00

    borgbackup is an opensource, deduplicating archiver with compression and authenticated encryption. A flaw in the cryptographic authentication scheme in borgbackup allowed an attacker to fake archives and potentially indirectly cause backup data loss in the repository. The attack…