CVE-2020-27637

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
12/01/2021
Last modified:
06/01/2024

Description

The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:r-project:cran:*:*:*:*:*:*:*:* 4.0.3 (excluding)