PT-2021-11413 · R · R
Chris Davis
+1
·
Published
2021-01-12
·
Updated
2024-01-06
·
CVE-2020-27637
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
R versions prior to 4.0.3
Description:
The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the
install.packages() function from the interpreter.Recommendations:
Update to version 4.0.3 to resolve the issue. As a temporary workaround, consider restricting the use of the
install.packages() function and the R CMD install cli command until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
R