Improper Link Resolution Before File Access ('Link Following') (CWE-59)
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which could be utilized to run arbitrary commands on the target system.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
NVD published the first details for CVE-2023-7216
Feedly found the first article mentioning CVE-2023-7216. See article
RedHat CVE advisory released a security advisory (CVE-2023-7216).
EPSS Score was set to: 0.14% (Percentile: 48.6%)
A CVSS base score of 5.3 has been assigned.