Lucene search

K
osvGoogleOSV:GO-2020-0042
HistoryApr 14, 2021 - 8:04 p.m.

Arbitrary File Write via Archive Extraction (Zip Slip) in github.com/sassoftware/go-rpmutils

2021-04-1420:04:52
Google
osv.dev
15
file extraction
rpm vulnerability
improper path sanitization
relative file paths
target directory
software

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

40.0%

Due to improper path sanitization, RPMs containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

40.0%