First published: Tue Mar 29 2022(Updated: )
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
Credit: security@joomla.org security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/joomla/archive | <1.1.12>=2.0.0<2.0.1 | |
Joomla Joomla\! | >=3.0.0<=3.10.6 | |
Joomla Joomla\! | >=4.0.0<=4.1.0 | |
composer/joomla/archive | >=2.0.0<2.0.1 | 2.0.1 |
composer/joomla/archive | <1.1.12 | 1.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-23793.
The title of the vulnerability is Path Traversal within joomla/archive tar class.
The severity of the vulnerability is not specified.
The vulnerability affects the Joomla archive package with versions 1.1.12 up to exclusive 2.0.1.
To fix the vulnerability, update the Joomla archive package to a version higher than 2.0.1.