Home / Companies / JFrog / Blog / Post Details
Content Deep Dive

Follow the Data: A Hidden Directory Traversal Vulnerability in QNX Slinger

Blog post from JFrog

Post Details
Company
Date Published
Author
Asaf Karas and Ilya Khivrich
Word Count
1,064
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

The blog post discusses the discovery and analysis of a directory traversal vulnerability in the QNX Slinger HTTP server, part of the BlackBerry QNX operating system commonly used in the automotive industry. This vulnerability arises due to an improper sequence of sanitization and URI decoding, allowing attackers to manipulate file paths using encoded sequences to access unauthorized files or execute remote code. The flaw, identified as CVE-2020-6932 with a CVSSv3 score of 10, limits impact due to minimal permissions but still poses a significant security risk. JFrog's security research team emphasizes the importance of automated security analysis and adherence to stringent security guidelines to prevent such vulnerabilities. The issue was responsibly disclosed to BlackBerry, which responded promptly, and the blog encourages further discussion on security vulnerabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.