Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-14352

21
FAUCET Score

CVE-2020-14352 is a directory traversal vulnerability in librepo versions prior to 1.12.1, affecting products like fedoraproject, opensuse, and redhat. An attacker controlling a remote repository could exploit this flaw to write files outside the intended destination, potentially leading to system compromise by overwriting critical system files. This vulnerability carries a high CVSS score of 8.0, indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability, primarily threatening users of untrusted third-party repositories. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.12.1CPE matchmatch criteria
cpe:2.3:a:redhat:librepo:*:*:*:*:*:*:*:*
15.0CPE matchmatch criteria
cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:*
15.2CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.1
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.53%
Probability of exploitation in next 30 days
EPSS Percentile
83.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0253 is in the 95th percentile among its peer group of 890 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 1.11.0-3
microsoftpatch availablevia msrc
Product: 19154-16820Fixed in: 1.11.0-3
microsoftpatch availablevia msrc
Product: cm1 librepo 1.11.0-3 on CBL Mariner 1.0Fixed in: 1.11.0-3
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 1.11.0-3
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Extended Update SupportFixed in: librepo-0:1.10.3-4.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsFixed in: librepo-0:1.9.2-2.el8_0
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: librepo-0:1.8.1-8.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: librepo-0:1.11.0-3.el8_2
View patch
susepatch availablevia nvd_reference
View patch

Vendor Advisories (3)

microsoft2020-Nov/CVE-2020-14352

CVE-2020-14352

Nov 10, 2020
redhatCVE-2020-14352Important

librepo: missing path validation in repomd.xml may lead to directory traversal

Aug 13, 2020
microsoft2020-Aug/CVE-2020-14352Important

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.

Aug 11, 2020

References

lists.opensuse.org / opensuse-security-announce/2020-08/msg00072.html
Mailing ListPatchThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2020-09/msg00055.html
Mailing ListThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/33RX4P5R5YL4NZSFSE4NOX37X6YCXAS4
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/OOMDEQBRJ7SO2QWL7H23G3VV2VSCUYOY
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/XDMHVY7OMIJNSPVZ2GJWHT77Z5V3YJ55