Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38530
HistoryDec 20, 2022 - 3:39 a.m.

Arbitrary File Write

2022-12-2003:39:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
guarddog
arbitrary file write
unsafe extracting

EPSS

0.001

Percentile

42.3%

GuardDog is vulnerable to arbitrary file write. The vulnerability exists due to the unsafe extracting using the shutil.unpack_archive functionality in the download_compressed function of package_scanner.py, allowing an attacker to write arbitrary files outside the destination directory through a malicious tarball archive.

EPSS

0.001

Percentile

42.3%

Related for VERACODE:38530