CVE-2024-10389
HIGHGoogle Safearchive < 2024-10-25 - Path Traversal
Title source: ruleDescription
There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc
Scores
CVSS v3
7.5
EPSS
0.0003
EPSS Percentile
8.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-22
CWE-427
Status
published
Affected Products (2)
google/safearchive
< 2024-10-25
google/safearchive
< 0.0.0-20241025131057-f7ce9d7b6f9cGo
Timeline
Published
Nov 04, 2024
Tracked Since
Feb 18, 2026