Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-41140

Опубликовано: 24 апр. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 8.7

Описание

Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where tarfile.data_filter is unavailable. Considering only Python versions which are still supported by Poetry, these are 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4. This vulnerability is fixed in 2.3.4.

РелизСтатусПримечание
devel

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/resolute

needed

jammy

needed

noble

needed

questing

ignored

end of life, was needed
resolute

needed

upstream

needed

Показывать по

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
redhat
3 месяца назад

Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where tarfile.data_filter is unavailable. Considering only Python versions which are still supported by Poetry, these are 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4. This vulnerability is fixed in 2.3.4.

CVSS3: 8.7
nvd
3 месяца назад

Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions where tarfile.data_filter is unavailable. Considering only Python versions which are still supported by Poetry, these are 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4. This vulnerability is fixed in 2.3.4.

msrc
3 месяца назад

Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4

CVSS3: 8.7
debian
3 месяца назад

Poetry is a dependency manager for Python. Prior to 2.3.4, the extract ...

github
3 месяца назад

Poetry has Path Traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4

8.7 High

CVSS3