Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade busybox | Jul 30, 2024 | Aug 7, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 7, 2017 |
| Suse | — | Upgrade busyboxUpgrade busybox-testsuiteUpgrade busybox-staticUpgrade busybox-warewulf3 | Aug 9, 2024 | Oct 21, 2015 |
| Ubuntu | — | Upgrade udhcpdUpgrade busybox-staticUpgrade busyboxUpgrade busybox-initramfsUpgrade udhcpc | Apr 10, 2019 | Aug 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub