CVE-2024-10389

HIGH

Safearchive < 0.0.0-20241025131057-f7ce9d7b6f9c - Path Traversal and Arbitrary File Write via Symbolic Link Extraction

Title source: llm
STIX 2.1

Description

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 9.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-427
Status published
Products (2)
google/safearchive < 2024-10-25
google/safearchive 0 - 0.0.0-20241025131057-f7ce9d7b6f9cGo
Published Nov 04, 2024
Tracked Since Feb 18, 2026