There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc
Metrics
Affected Vendors & Products
References
History
Mon, 04 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc | |
Title | Path Traversal in Safearchive | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: Google
Published: 2024-11-04T10:47:39.434Z
Updated: 2024-11-04T16:02:53.913Z
Reserved: 2024-10-25T13:24:51.342Z
Link: CVE-2024-10389
Vulnrichment
Updated: 2024-11-04T16:02:40.349Z
NVD
Status : Awaiting Analysis
Published: 2024-11-04T11:15:04.647
Modified: 2024-11-04T18:50:05.607
Link: CVE-2024-10389
Redhat
No data.