CVE-2020-7669 is a high-severity path traversal vulnerability affecting all versions of the github.com/u-root/u-root/pkg/tarutil package. This flaw allows attackers to extract files to arbitrary locations on a system by manipulating relative paths within a tar archive, potentially leading to data corruption or system compromise. With a CVSS score of 7.5, this vulnerability is easily exploitable over a network with low attack complexity and no user interaction required. While there is no evidence of active exploitation, nor publicly available exploit code, the lack of community discussion and media coverage is typical for most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:u-root:u-root:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.