CVE-2020-7666
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
01/09/2020
Last modified:
04/09/2020
Description
This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relative path traversal attacks and symlink based (relative and absolute) path traversal attacks in cpio file extraction.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:u-root:u-root:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



