216.73.217.22

CVE-2025-48387

· Published 02/06/2025 20:15 · Modified 02/06/2025 20:15

Labels: CVE-2025-48387 2025-06-02CVE-2025-48387CWE-22[email protected]

Essential information

Published
02/06/2025 20:15
Modified
02/06/2025 20:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tar-fs / tar-fs cpe:2.3:a:tar-fs:tar-fs:<3.0.9:*:*:*:*:*:*:*
tar-fs / tar-fs cpe:2.3:a:tar-fs:tar-fs:<2.1.3:*:*:*:*:*:*:*
tar-fs / tar-fs cpe:2.3:a:tar-fs:tar-fs:<1.16.5:*:*:*:*:*:*:*

References