Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf2w-jqmq-fcm8

Опубликовано: 30 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2
CVSS3: 5.3

Описание

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

EPSS

Процентиль: 18%
0.00264
Низкий

2 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5
redhat
около 1 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5.3
nvd
около 1 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

msrc
28 дней назад

Tarfile.extract() doesn't fully respect filter parameter

CVSS3: 5.3
debian
около 1 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed ...

EPSS

Процентиль: 18%
0.00264
Низкий

2 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-281