CVE-2024-47877

CVSS V2 None CVSS V3 None
Description
Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to implement the new methods that have been added.
Overview
  • CVE ID
  • CVE-2024-47877
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-10-11T16:36:29.763Z
  • Last Modified Date
  • 2024-10-11T17:49:34.466Z
History
Created Old Value New Value Data Type Notes
2024-10-12 13:28:49 Added to TrackCVE