Описание
Path Traversal within joomla/archive zip class
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-26028
- https://github.com/joomla-framework/archive/commit/32c9009a1020d16bc1060c0d06339898b697cf2c
- https://developer.joomla.org/security-centre/848-20210308-core-path-traversal-within-joomla-archive-zip-class.html
- https://github.com/FriendsOfPHP/security-advisories/blob/master/joomla/archive/CVE-2021-26028.yaml
Пакеты
Наименование
joomla/archive
composer
Затронутые версииВерсия исправления
< 1.1.10
1.1.10
Связанные уязвимости
CVSS3: 5.5
nvd
почти 5 лет назад
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.