CVE-2023-39810: Path Traversal
Published Aug 28, 2023
·Updated
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
Affected Software
6 affected componentsFixes available
Busybox Busybox=1.30.1
Busybox Busybox=1.33.2
debian/busybox<=1:1.30.1-6, <=1:1.30.1-6+deb11u1, <=1:1.35.0-4, <=1:1.37.0-4
Microsoft cbl2 busybox 1.35.0-14<1.35.0-14
1.35.0-14
Microsoft azl3 busybox 1.36.1-12<1.36.1-11
1.36.1-11
Microsoft azl3 busybox 1.36.1-11<1.36.1-11
1.36.1-11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.36.1-11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.35.0-14
Event History
Aug 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
May 6, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-39810?
CVE-2023-39810 is an issue in the CPIO command of Busybox v1.33.2 that allows attackers to execute a directory traversal.
2
How severe is CVE-2023-39810?
CVE-2023-39810 has a severity rating of 7.8 (high).
3
Which software versions are affected by CVE-2023-39810?
CVE-2023-39810 affects Busybox v1.30.1 and v1.33.2.
4
How can attackers exploit CVE-2023-39810?
Attackers can exploit CVE-2023-39810 by executing a directory traversal.
5
Are there any references for CVE-2023-39810?
For more information on CVE-2023-39810, you can visit the Busybox website and the blog post by Pentagrid.