Bug 2242288 (CVE-2023-37460)
Summary: | CVE-2023-37460 plexus-archiver: Arbitrary File Creation in AbstractUnArchiver | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sandipan Roy <saroy> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | aazores, adupliak, aileenc, alampare, alazarot, anstephe, aschwart, asoldano, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, ccranfor, cdewolf, chazlett, chfoley, cmah, cmiranda, cmoulliard, csutherl, darran.lofthouse, dbruscin, dhanak, dkreling, dosoudil, drichtar, drosa, dsimansk, eaguilar, ebaron, emingora, epacific, eric.wittmann, fjuma, fmariani, fmongiar, gmalinko, haoli, hkataria, ibek, ikanello, istudens, ivassile, iweiss, jajackso, janstey, jcammara, jcantril, jclere, jhardy, jkang, jmitchel, jneedle, jnethert, jobarker, jolong, jpallich, jpechane, jpoth, jrokos, jscholz, kegrant, kingland, koliveir, kshier, kvanderr, kverlaen, lbacciot, lball, lgao, lthon, mabashia, matzew, mmadzin, mnovotny, mosmerov, mposolda, msochure, mstefank, msvehla, mulliken, nipatil, nwallace, pantinor, pbizzarr, pbraun, pcongius, pdelbell, pdrozd, peholase, pesilva, pgallagh, pjindal, plodge, pmackay, pskopek, rguimara, rhuss, rjohnson, rkieley, rkubis, rojacob, rowaters, rruss, rstancel, rstepani, saroy, sausingh, sfroberg, shvarugh, simaishi, smaestri, smcdonal, ssilvert, stcannon, sthorger, swoodman, szappis, tcunning, teagle, tfister, thavo, tom.jenkinson, vmuzikar, yfang, yguenane, zsadeh |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | plexus-archiver 4.8.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the Plexus Archiver. While using AbstractUnArchiver for extracting, an archive might lead to arbitrary file creation and possible remote code execution (RCE). Extracting an archive with an entry in the destination directory as a symbolic link whose target does not exist will bypass the directory destination verification.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2242516, 2242517 | ||
Bug Blocks: | 2242289 |
Description
Sandipan Roy
2023-10-05 11:11:17 UTC
Created plexus-archiver tracking bugs for this issue: Affects: fedora-37 [bug 2242516] Affects: fedora-38 [bug 2242517] This issue has been addressed in the following products: Migration Toolkit for Runtimes 1 on RHEL 8 Via RHSA-2023:6138 https://access.redhat.com/errata/RHSA-2023:6138 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2023:6886 https://access.redhat.com/errata/RHSA-2023:6886 |