mafintosh tar-fs
cpe:2.3:a:tar-fs_project:tar-fs:*:*:*:*:*:*:*
- < 3.1.1
- < 2.1.3
- < 1.16.5
A symlink validation bypass vulnerability has been identified in tar-fs versions prior to 3.1.1, 2.1.3, and 1.16.5. This vulnerability arises when the destination directory is predictable with a specific tarball, allowing for potential exploitation.
Exploitation of this vulnerability could lead to unauthorized manipulation of symlinks, potentially causing files to be overwritten or read inappropriately.
Users can upgrade to tar-fs versions 3.1.1, 2.1.4, or 1.16.6 to address this vulnerability. Alternatively, the ignore option can be used to bypass non-file and non-directory entries, such as symlinks.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.