Backblaze records
4 published records for vendor backblaze.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition2
- CWE-269 Improper Privilege Management1
- CWE-295 Improper Certificate Validation1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2020-8289Proof of concept | Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` backblaze · backblaze · CWE-295 | High7.8 | — | 4.7% | Dec 26, 2020 |
31Monitor | CVE-2020-8290Proof of concept | Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack backblaze · backblaze · CWE-269 | High7.8 | — | 0.6% | Dec 26, 2020 |
18Monitor | CVE-2022-23651No exploit | b2-sdk-python TOCTOU application key disclosurebackblaze · b2 python software development kit · CWE-367 | Medium4.7 | — | 0.2% | Feb 23, 2022 |
18Monitor | CVE-2022-23653No exploit | B2 Command Line Tool TOCTOU application key disclosurebackblaze · b2 command line tool · CWE-367 | Medium4.7 | — | 0.2% | Feb 23, 2022 |
- CVE-2020-828932Monitor
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit`
HighCVSS 7.8Proof of conceptEPSS 5%backblaze · backblazeDec 26, 2020
- CVE-2020-829031Monitor
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack
HighCVSS 7.8Proof of conceptEPSS 1%backblaze · backblazeDec 26, 2020
- CVE-2022-2365118Monitor
b2-sdk-python TOCTOU application key disclosure
MediumCVSS 4.7No exploitEPSS 0%backblaze · b2 python software development kitFeb 23, 2022
- CVE-2022-2365318Monitor
B2 Command Line Tool TOCTOU application key disclosure
MediumCVSS 4.7No exploitEPSS 0%backblaze · b2 command line toolFeb 23, 2022