Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3298 | There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc |
Github GHSA |
GHSA-q3rp-vvm7-j8jg | Safearchive Path Traversal vulnerability |
Wed, 23 Jul 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google safearchive |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:google:safearchive:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Google
Google safearchive |
|
| Metrics |
cvssV3_1
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc | |
| Title | Path Traversal in Safearchive | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-11-21T16:25:29.258Z
Reserved: 2024-10-25T13:24:51.342Z
Link: CVE-2024-10389
Updated: 2024-11-04T16:02:40.349Z
Status : Analyzed
Published: 2024-11-04T11:15:04.647
Modified: 2025-07-23T19:28:31.400
Link: CVE-2024-10389
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA