In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501. Reference: https://github.com/eldy/awstats/issues/90
Created awstats tracking bugs for this issue: Affects: epel-all [bug 1911650] Affects: fedora-all [bug 1911649]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
FEDORA-2020-d1aa0e030c has been pushed to the Fedora 32 stable repository. If problem still persists, please make note of it in this bug report.