Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2999 | Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to implement the new methods that have been added. |
Github GHSA |
GHSA-8rm2-93mq-jqhc | Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory. |
Fri, 22 Nov 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:codeclysm:extract:*:*:*:*:*:go:*:* | |
| Metrics |
cvssV3_1
|
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codeclysm
Codeclysm extract |
|
| CPEs | cpe:2.3:a:codeclysm:extract:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Codeclysm
Codeclysm extract |
|
| Metrics |
ssvc
|
Fri, 11 Oct 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to implement the new methods that have been added. | |
| Title | Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory. | |
| Weaknesses | CWE-22 CWE-61 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-11T17:49:34.466Z
Reserved: 2024-10-04T16:00:09.630Z
Link: CVE-2024-47877
Updated: 2024-10-11T17:49:23.469Z
Status : Analyzed
Published: 2024-10-11T17:15:04.450
Modified: 2024-11-22T19:30:48.913
Link: CVE-2024-47877
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA