CVE-2024-10389

HIGH

Google Safearchive < 2024-10-25 - Path Traversal

Title source: rule

Description

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-22 CWE-427
Status published

Affected Products (2)

google/safearchive < 2024-10-25
google/safearchive < 0.0.0-20241025131057-f7ce9d7b6f9cGo

Timeline

Published Nov 04, 2024
Tracked Since Feb 18, 2026