🟢 Authenticated Backup Metadata Hooks Execution Bypass

Summary

The Backup module executes some restore hooks even when told not to by the user performing restoration of a backup file, potentially resulting in command injection as the asterisk user.

Authentication with a known username is required to run the restore. But before that, write access to the backup files is required to craft the malicious hook scripts.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-rvwr-xrpc-4hf4

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

Highlights

:green_circle: