ASA-202007-1 - log back

ASA-202007-1 edited at 29 Jul 2020 19:30:37
ASA-202007-1 edited at 14 Jul 2020 15:39:18
Impact
+ A remote attacker might be able to trigger cross-site scripting, bypass the sandbox and execute arbitrary code on the affected host.
ASA-202007-1 created at 14 Jul 2020 15:38:44
ASA-202007-1 deleted at 14 Jul 2020 15:32:47
Workaround
- Disable the webserver or set a password via "webserver-password". Additionally, restrict the binding address using the `webserver-address` setting to local addresses only and/or use a firewall to disallow web requests from untrusted sources reaching the webserver listening address.
Impact
- A remote attacker can bypass the ACL restriction set on the internal webserver.
ASA-202007-1 edited at 07 Jul 2020 15:15:40
Workaround
+ Disable the webserver or set a password via "webserver-password". Additionally, restrict the binding address using the `webserver-address` setting to local addresses only and/or use a firewall to disallow web requests from untrusted sources reaching the webserver listening address.
Impact
+ A remote attacker can bypass the ACL restriction set on the internal webserver.
ASA-202007-1 created at 07 Jul 2020 15:14:06