Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45016
HistoryJan 12, 2024 - 9:49 p.m.

Path Traversal

2024-01-1221:49:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
path traversal
cpio
vulnerability
lack of validation

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

7

Confidence

High

EPSS

0

Percentile

15.5%

cpio is vulnerable to Path Traversal. The vulnerability is due to a lack of validation for filenames. This potentially leads to Path Traversal.

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

7

Confidence

High

EPSS

0

Percentile

15.5%