Home
CRITICAL: 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HDefault status
unaffected
0.0.0 (2.7.1)
affected
Description
BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
0.0.0 (2.7.1)
References
blog.blacklanternsecurity.com/...security-advisory-gitdumper