Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9423-6c93-gpp8

Опубликовано: 23 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)

The CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading .. which leads in file extraction outside of the current directory. Note, the fixing commit was applied to all affected versions which were re-released.

Пакеты

Наименование

github.com/sassoftware/go-rpmutils

go
Затронутые версииВерсия исправления

< 0.1.0

0.1.0

EPSS

Процентиль: 61%
0.00414
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading ".." which leads in file extraction outside of the current directory. Note: the fixing commit was applied to all affected versions which were re-released.

EPSS

Процентиль: 61%
0.00414
Низкий

7.5 High

CVSS3

Дефекты

CWE-22