← לוח פגיעויות

CVE-2025-4435

גבוהה 7.5

תיאור (מקור, אנגלית)

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS — סבירות ניצול
1% (אחוזון 000) נכון ל-20/9/2026
CWE
CWE-682

קישורים