Loading HuntDB...

GHSA-jm67-jh3g-cg3f

GitHub Security Advisory

Path Traversal within joomla/archive tar class

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.

Affected Packages

Packagist joomla/archive
Affected versions: 0 (fixed in 1.1.12)
Packagist joomla/archive
Affected versions: 2.0.0 (fixed in 2.0.1)

Related CVEs

Key Information

GHSA ID
GHSA-jm67-jh3g-cg3f
Published
March 31, 2022 12:00 AM
Last Modified
May 15, 2024 9:04 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
joomla/archive
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.