Skip to content

mat2 before 0.13.0 allows directory traversal during the ZIP archive cleaning process.

Moderate severity GitHub Reviewed Published Jul 12, 2022 to the GitHub Advisory Database • Updated Jan 29, 2023

Package

pip mat2 (pip)

Affected versions

>= 0, < 0.13.0

Patched versions

0.13.0

Description

mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.

References

Published by the National Vulnerability Database Jul 8, 2022
Published to the GitHub Advisory Database Jul 12, 2022
Reviewed Jul 12, 2022
Last updated Jan 29, 2023

Severity

Moderate

Weaknesses

CVE ID

CVE-2022-35410

GHSA ID

GHSA-f33p-9287-h552
Checking history
See something to contribute? Suggest improvements for this vulnerability.