Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

ΠšΠΎΠ»ΠΈΡ‡Π΅ΡΡ‚Π²ΠΎ 36

ΠšΠΎΠ»ΠΈΡ‡Π΅ΡΡ‚Π²ΠΎ 36

github Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

GHSA-4g4g-fqw4-prp2

большС 1 года назад

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions...

CVSS3: 7.5
EPSS: Низкий
ubuntu Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2025-4138

большС 1 года назад

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid install...

CVSS3: 7.5
EPSS: Низкий
redhat Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2025-4138

большС 1 года назад

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid insta...

CVSS3: 7.5
EPSS: Низкий
nvd Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2025-4138

большС 1 года назад

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid inst

CVSS3: 7.5
EPSS: Низкий
msrc Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2025-4138

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory

CVSS3: 7.5
EPSS: Низкий
debian Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2025-4138

большС 1 года назад

Allows the extraction filter to be ignored, allowing symlink targets t ...

CVSS3: 7.5
EPSS: Низкий
fstec Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

BDU:2025-09992

большС 1 года назад

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ модуля tarfile ΠΈΠ½Ρ‚Π΅Ρ€ΠΏΡ€Π΅Ρ‚Π°Ρ‚ΠΎΡ€Π° языка программирования Python (CPython), ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡŽΡ‰Π°Ρ Π½Π°Ρ€ΡƒΡˆΠΈΡ‚Π΅Π»ΡŽ ΠΏΠΎΠ»ΡƒΡ‡ΠΈΡ‚ΡŒ нСсанкционированный доступ ΠΊ Π·Π°Ρ‰ΠΈΡ‰Π°Π΅ΠΌΠΎΠΉ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΠΈ

CVSS3: 7.5
EPSS: Низкий
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

SUSE-SU-2025:02057-1

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

Security update for python311

EPSS: Низкий
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

SUSE-SU-2025:02050-1

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

Security update for python39

EPSS: Низкий
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

SUSE-SU-2025:02049-1

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

Security update for python311

EPSS: Низкий
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

SUSE-SU-2025:02048-1

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

Security update for python312

EPSS: Низкий
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

SUSE-SU-2025:02047-1

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

Security update for python310

EPSS: Низкий
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

RLSA-2025:10189

12 мСсяцСв Π½Π°Π·Π°Π΄

Important: python3.12 security update

EPSS: Низкий
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

RLSA-2025:10148

12 мСсяцСв Π½Π°Π·Π°Π΄

Important: python3.11 security update

EPSS: Низкий
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

RLSA-2025:10140

12 мСсяцСв Π½Π°Π·Π°Π΄

Important: python3.12 security update

EPSS: Низкий
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

RLSA-2025:10136

12 мСсяцСв Π½Π°Π·Π°Π΄

Important: python3.9 security update

EPSS: Низкий
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

RLSA-2025:10128

4 мСсяца Π½Π°Π·Π°Π΄

Important: python3 security update

EPSS: Низкий
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

RLSA-2025:10031

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

Important: python3.12 security update

EPSS: Низкий
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

RLSA-2025:10026

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

Important: python3.11 security update

EPSS: Низкий
oracle-oval Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

ELSA-2025-10189

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

ELSA-2025-10189: python3.12 security update (IMPORTANT)

EPSS: Низкий

УязвимостСй Π½Π° страницу

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ
CVSS
EPSS
ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ
github Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
GHSA-4g4g-fqw4-prp2

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions...

CVSS3: 7.5
1%
Низкий
большС 1 года назад
ubuntu Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
CVE-2025-4138

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid install...

CVSS3: 7.5
1%
Низкий
большС 1 года назад
redhat Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
CVE-2025-4138

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid insta...

CVSS3: 7.5
1%
Низкий
большС 1 года назад
nvd Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
CVE-2025-4138

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfileΒ module to extract untrusted tar archives using TarFile.extractall()Β or TarFile.extract()Β using the filter=Β parameter with a value of "data"Β or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter Β for more information. Note that for Python 3.14 or later the default value of filter=Β changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid inst

CVSS3: 7.5
1%
Низкий
большС 1 года назад
msrc Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
CVE-2025-4138

Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory

CVSS3: 7.5
1%
Низкий
ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄
debian Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
CVE-2025-4138

Allows the extraction filter to be ignored, allowing symlink targets t ...

CVSS3: 7.5
1%
Низкий
большС 1 года назад
fstec Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
BDU:2025-09992

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ модуля tarfile ΠΈΠ½Ρ‚Π΅Ρ€ΠΏΡ€Π΅Ρ‚Π°Ρ‚ΠΎΡ€Π° языка программирования Python (CPython), ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡŽΡ‰Π°Ρ Π½Π°Ρ€ΡƒΡˆΠΈΡ‚Π΅Π»ΡŽ ΠΏΠΎΠ»ΡƒΡ‡ΠΈΡ‚ΡŒ нСсанкционированный доступ ΠΊ Π·Π°Ρ‰ΠΈΡ‰Π°Π΅ΠΌΠΎΠΉ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΠΈ

CVSS3: 7.5
1%
Низкий
большС 1 года назад
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
SUSE-SU-2025:02057-1

Security update for python311

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
SUSE-SU-2025:02050-1

Security update for python39

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
SUSE-SU-2025:02049-1

Security update for python311

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
SUSE-SU-2025:02048-1

Security update for python312

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄
suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
SUSE-SU-2025:02047-1

Security update for python310

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
RLSA-2025:10189

Important: python3.12 security update

12 мСсяцСв Π½Π°Π·Π°Π΄
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
RLSA-2025:10148

Important: python3.11 security update

12 мСсяцСв Π½Π°Π·Π°Π΄
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
RLSA-2025:10140

Important: python3.12 security update

12 мСсяцСв Π½Π°Π·Π°Π΄
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
RLSA-2025:10136

Important: python3.9 security update

12 мСсяцСв Π½Π°Π·Π°Π΄
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
RLSA-2025:10128

Important: python3 security update

4 мСсяца Π½Π°Π·Π°Π΄
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
RLSA-2025:10031

Important: python3.12 security update

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄
rocky Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
RLSA-2025:10026

Important: python3.11 security update

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄
oracle-oval Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ
ELSA-2025-10189

ELSA-2025-10189: python3.12 security update (IMPORTANT)

ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

УязвимостСй Π½Π° страницу

exploitDog - КомплСксноС Ρ€Π΅ΡˆΠ΅Π½ΠΈΠ΅ для обнаруТСния, ΠΎΡ†Π΅Π½ΠΊΠΈ ΠΈ устранСния уязвимостСй.