{"id":"GHSA-jm67-jh3g-cg3f","summary":"Path Traversal within joomla/archive tar class","details":"An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.","aliases":["BIT-joomla-2022-23793","CVE-2022-23793"],"modified":"2025-04-03T15:26:51.299801Z","published":"2022-03-31T00:00:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-05-15T21:04:31Z","nvd_published_at":"2022-03-30T16:15:00Z","cwe_ids":["CWE-22"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23793"},{"type":"WEB","url":"https://developer.joomla.org/security-centre/870-20220301-core-zip-slip-within-the-tar-extractor.html"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/joomla/archive/CVE-2022-23793.yaml"},{"type":"PACKAGE","url":"https://github.com/joomla-framework/archive"},{"type":"WEB","url":"http://packetstormsecurity.com/files/166546/Joomla-4.1.0-Zip-Slip-File-Overwrite-Path-Traversal.html"}],"affected":[{"package":{"name":"joomla/archive","ecosystem":"Packagist","purl":"pkg:composer/joomla/archive"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.12"}]}],"versions":["1.0","1.0-alpha","1.0-beta","1.0-beta2","1.0-beta3","1.1.0","1.1.1","1.1.10","1.1.11","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-jm67-jh3g-cg3f/GHSA-jm67-jh3g-cg3f.json"}},{"package":{"name":"joomla/archive","ecosystem":"Packagist","purl":"pkg:composer/joomla/archive"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.1"}]}],"versions":["2.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-jm67-jh3g-cg3f/GHSA-jm67-jh3g-cg3f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}