PT-2020-19694 · U Root · U-Root

Georgios Gkitsas

·

Published

2020-09-01

·

Updated

2024-04-24

·

CVE-2020-7666

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions u-root versions prior to 7.0.0
Description The issue affects the cpio file extraction in the u-root package, making it vulnerable to leading and non-leading relative path traversal attacks, as well as symlink-based path traversal attacks, both relative and absolute.
Recommendations For versions prior to 7.0.0, update to version 7.0.0 or later to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-7666
GHSA-MQ35-X99R-54FC
SNYK-GOLANG-GITHUBCOMUROOTUROOTPKGCPIO-570440

Affected Products

U-Root