On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12.1.5, 11.6.4-11.6.5, and 11.5.9-11.5.10, the access controls implemented by scp.whitelist and scp.blacklist are not properly enforced for paths that are symlinks. This allows authenticated users with SCP access to overwrite certain configuration files that would otherwise be restricted.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published: 2019-12-23T17:06:16

Updated: 2024-08-04T20:31:03.595Z

Reserved: 2019-01-22T00:00:00

Link: CVE-2019-6679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-12-23T18:15:11.160

Modified: 2020-01-02T20:33:43.133

Link: CVE-2019-6679

cve-icon Redhat

No data.