github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)
High severity
GitHub Reviewed
Published
Jun 23, 2021
to the GitHub Advisory Database
•
Updated Aug 29, 2023
Description
Published by the National Vulnerability Database
Jun 24, 2020
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
Jun 23, 2021
Last updated
Aug 29, 2023
The CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading
..
which leads in file extraction outside of the current directory. Note, the fixing commit was applied to all affected versions which were re-released.References