Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rhh4-rh7c-7r5v

Опубликовано: 06 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Archiver Path Traversal vulnerability

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

Пакеты

Наименование

github.com/mholt/archiver/v3

go
Затронутые версииВерсия исправления

>= 3.0.0, <= 3.5.1

Отсутствует

Наименование

github.com/mholt/archiver

go
Затронутые версииВерсия исправления

>= 3.0.0, <= 3.5.1

Отсутствует

EPSS

Процентиль: 95%
0.17294
Средний

6.1 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.1
redhat
около 2 лет назад

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

CVSS3: 6.1
nvd
почти 2 года назад

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

suse-cvrf
около 2 месяцев назад

Security update for hauler

EPSS

Процентиль: 95%
0.17294
Средний

6.1 Medium

CVSS3

Дефекты

CWE-22