Количество 2
Количество 2
CVE-2020-7666
больше 5 лет назад
This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relative path traversal attacks and symlink based (relative and absolute) path traversal attacks in cpio file extraction.
CVSS3: 7.5
EPSS: Низкий
GHSA-mq35-x99r-54fc
почти 2 года назад
github.com/u-root/u-root/pkg/cpio Arbitrary File Write via Archive Extraction (Zip Slip)
CVSS3: 7.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-7666 This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relative path traversal attacks and symlink based (relative and absolute) path traversal attacks in cpio file extraction. | CVSS3: 7.5 | 1% Низкий | больше 5 лет назад | |
GHSA-mq35-x99r-54fc github.com/u-root/u-root/pkg/cpio Arbitrary File Write via Archive Extraction (Zip Slip) | CVSS3: 7.5 | 1% Низкий | почти 2 года назад |
Уязвимостей на страницу
20