CVE-2020-7668

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
23/06/2020
Last modified:
01/01/2022

Description

In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:compression_and_archive_extensions_tz_project:compression_and_archive_extensions_tz_project:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools