Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29022
HistoryJan 19, 2021 - 1:26 a.m.

Directory Traversal

2021-01-1901:26:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
directory traversal
symbolic links
symlink attacks
vulnerability

EPSS

0.882

Percentile

98.7%

archive_tar is vulnerable to directory traversal. The vulnerability exists due to the lack of sanitization of symbolic links to out-of-path filenames, allowing an attacker to inject ../ characters in a file or folder name to perform symlink attacks.