Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
Vulnerability Description
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
tar-fs 安全漏洞
Vulnerability Description
tar-fs是Mathias Buus个人开发者的一款tar-stream的文件系统绑定。 tar-fs 3.1.1之前版本、2.1.3版本和1.16.5版本存在安全漏洞,该漏洞源于可预测目标目录时可能绕过符号链接验证。
CVSS Information
N/A
Vulnerability Type
N/A