RubySec

Providing security resources for the Ruby community

CVE-2017-1000026 (mixlib-archive): mixlib-archive Path Traversal vulnerability

mixlib-archive Path Traversal vulnerability

Published: May 13, 2022

SECURITY IDENTIFIERS

GEM

mixlib-archive

SEVERITY

CVSS v3.x: 7.5 (High)

PATCHED VERSIONS

>= 0.4.0

DESCRIPTION

Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using .. in tar archive entries

RELATED