CVE-2020-27637 - log back

CVE-2020-27637 edited at 12 Jan 2021 08:38:59
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ The R programming language's default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. The issue is fixed in version 4.0.3.
References
+ https://labs.bishopfox.com/advisories/cran-version-4.0.2
Notes
CVE-2020-27637 created at 12 Jan 2021 08:36:57