A TarSlip vulnerability exists in the deepjavalibrary/djl, affecting version 0.26.0 and fixed in version 0.27.0. This vulnerability allows an attacker to manipulate file paths within tar archives to overwrite arbitrary files on the target system. Exploitation of this vulnerability could lead to remote code execution, privilege escalation, data theft or manipulation, and denial of service. The vulnerability is due to improper validation of file paths during the extraction of tar files, as demonstrated in multiple occurrences within the library's codebase, including but not limited to the files_util.py and extract_imagenet.py scripts.
History

Thu, 26 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Djl
Djl deep Java Library
Weaknesses CWE-22
CPEs cpe:2.3:a:djl:deep_java_library:0.26.0:*:*:*:*:*:*:*
Vendors & Products Djl
Djl deep Java Library
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-06-06T17:55:55.145Z

Updated: 2024-08-01T19:25:42.176Z

Reserved: 2024-03-26T14:05:08.782Z

Link: CVE-2024-2914

cve-icon Vulnrichment

Updated: 2024-08-01T19:25:42.176Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-06T18:15:13.227

Modified: 2024-09-26T14:12:22.980

Link: CVE-2024-2914

cve-icon Redhat

No data.