GHSA-cwp3-834g-x79g – archive-tar-minitar
Package
Manager: gem
Name: archive-tar-minitar
Vulnerable Version: <0
Severity
Level: Medium
CVSS v3.1: N/A
CVSS v4.0: N/A
EPSS: N/A pctlN/A
Details
Moderate severity vulnerability that affects archive-tar-minitar and minitar Withdrawn, accidental duplicate publish. Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
Metadata
Created: 2018-08-21T17:07:36Z
Modified: 2020-06-16T21:39:02Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-cwp3-834g-x79g/GHSA-cwp3-834g-x79g.json
CWE IDs: []
Alternative ID: N/A
Finding: N/A
Auto approve: 0