Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-25046

Опубликовано: 27 дек. 2022
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

A flaw was found in the cloudfoundry/archiver package. In affected versions of this package, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory due to improper path sanitization.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Quay 3quay/quay-builder-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2157840cloudfoundry/archiver: improper path sanitization can result in files being extracted outside of the target directory

EPSS

Процентиль: 65%
0.01188
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
больше 3 лет назад

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

CVSS3: 9.1
github
больше 3 лет назад

Cloud Foundry Archiver vulnerable to path traversal

EPSS

Процентиль: 65%
0.01188
Низкий

9.1 Critical

CVSS3