CVE-2022-25358
18.02.2022, 22:15
A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.
Vendor | Product | Version |
---|---|---|
awful-salmonella-tar_project | awful-salmonella-tar | 𝑥 < 0.0.4 |
𝑥
= Vulnerable software versions
References