-
Notifications
You must be signed in to change notification settings - Fork 282
Closed
Labels
All For OneSubmissions to the All for One, One for All bountySubmissions to the All for One, One for All bounty
Description
Query PR
github/codeql#10851 (closed in favor of the next one)
github/codeql#10887
Language
Python
CVE(s) ID list
- https://huntr.dev/bounties/2d1db3c9-93e8-4902-a55b-5ea53c22aa11/
- https://huntr.dev/bounties/309725a2-bfc9-4ef3-a4c1-360a9f6b890b/
more to come.
CWE
CWE-022
Report
- TarSlip vulnerability.
- _Extracting files from a malicious tarball without validating that the destination file path is within the destination directory can cause files outside the destination directory to be overwritten, due to the possible presence of directory traversal elements (
..) in archive path names. - I have added more sources and sinks than I checked the combination use of both.
- Yes, I've checked the query against valid samples extracted from https://cs.github.com. I ethically reported them using https://huntr.dev (more to become public soon).
- This is my first contribution, and I would love to provide more.
Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc).
- Yes
- No
Blog post link
Metadata
Metadata
Assignees
Labels
All For OneSubmissions to the All for One, One for All bountySubmissions to the All for One, One for All bounty