« Volver al listado

CVE-2020-3996

Estado: ModificadaMedia (5.5)—

Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorized users.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-3996",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Velero",
          "versions": [
            {
              "status": "affected",
              "version": "Velero versions 0.* and 1.* prior to 1.4.3 and 1.5.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-10-22T21:15:14.247",
  "references": [
    {
      "url": "https://github.com/vmware-tanzu/velero/security/advisories/GHSA-72xg-3mcq-52v4",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://github.com/vmware-tanzu/velero/security/advisories/GHSA-72xg-3mcq-52v4",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorized users."
    },
    {
      "lang": "es",
      "value": "Velero (versiones anteriores a 1.4.3 y 1.5.2) en algunos casos no administra apropiadamente los identificadores de volumen, lo que puede resultar en una filtración de información para usuarios no autorizados"
    }
  ],
  "lastModified": "2026-06-17T03:19:24.100",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:velero:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB2A02AD-36BD-4664-8856-689F408DBB64",
              "versionEndExcluding": "1.4.3"
            },
            {
              "criteria": "cpe:2.3:a:vmware:velero:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F8684CB-4FCA-4DC3-95AE-37D7C93499D1",
              "versionEndExcluding": "1.5.2",
              "versionStartIncluding": "1.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}