First published: Tue Dec 27 2022(Updated: )
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
Credit: security@golang.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudfoundry Archiver | <2018-05-23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-25046 is a vulnerability that allows files to be written or overwritten outside of the target directory due to improper path sanitization in Cloudfoundry Archiver.
CVE-2018-25046 has a severity rating of 9.1 (Critical).
The affected software by CVE-2018-25046 is Cloudfoundry Archiver up to version 2018-05-23.
To fix CVE-2018-25046, it is recommended to update Cloudfoundry Archiver to a version that includes the fix.
The CWE (Common Weakness Enumeration) of CVE-2018-25046 is CWE-22.