Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31892
HistorySep 01, 2021 - 4:26 a.m.

Remote Code Execution (RCE)

2021-09-0104:26:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.001 Low

EPSS

Percentile

48.3%

tar is vulnerable to Remote Code Execution (RCE). An attacker is able to exploit the vulnerability by modifying the symbolic link. The vulnerability exists due to the lack of sanitization of the symbolic link thus allowing the system to extract file through a maliciously modified symbolic link.