CVE-2023-7216
published 2024-02-05CVE-2023-7216: A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially…
PriorityP432medium5.3CVSS 3.1
AVLACLPRNUIRSUCLILAL
EPSS
0.90%
56.0th percentile
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
osv5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-7216: A path traversal vulnerability was found in the CPIO utility
osv·2024-02-05·CVSS 5.3
CVE-2023-7216 [MEDIUM] CVE-2023-7216: A path traversal vulnerability was found in the CPIO utility
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.
GHSA
GHSA-v9vx-4mxw-76j2: A path traversal vulnerability was found in the CPIO utility
ghsa_unreviewed·2024-02-05
CVE-2023-7216 [HIGH] CWE-22 GHSA-v9vx-4mxw-76j2: A path traversal vulnerability was found in the CPIO utility
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which could be utilized to run arbitrary commands on the target system.
Red Hat
CPIO: extraction allows symlinks which enables Remote Command Execution
vendor_redhat·2024-02-05·CVSS 5.3
CVE-2023-7216 [MEDIUM] CWE-59 CPIO: extraction allows symlinks which enables Remote Command Execution
CPIO: extraction allows symlinks which enables Remote Command Execution
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.
Statement: This v
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-05
Published