CVE-2022-23793: [20220301] - Core - Zip Slip within the Tar extractor
Published Mar 29, 2022
·Updated
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
Other sources
Path Traversal within joomla/archive tar class
Affected Software
5 affected componentsFixes available
composer/joomla/archive<1.1.12, >=2.0.0, <2.0.1
composer/joomla/archive>=2.0.0<2.0.1
2.0.1
composer/joomla/archive<1.1.12
1.1.12
Joomla Joomla\!>=3.0.0<=3.10.6
Joomla Joomla\!>=4.0.0<=4.1.0
Event History
Mar 29, 2022
Advisory Published
06:00 PM
Mar 30, 2022
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-23793.
2
What is the title of the vulnerability?
The title of the vulnerability is Path Traversal within joomla/archive tar class.
3
What is the severity of the vulnerability?
The severity of the vulnerability is not specified.
4
Which software is affected by the vulnerability?
The vulnerability affects the Joomla archive package with versions 1.1.12 up to exclusive 2.0.1.
5
How can the vulnerability be fixed?
To fix the vulnerability, update the Joomla archive package to a version higher than 2.0.1.