CVE-2021-32610 - log back

CVE-2021-32610 edited at 27 Jul 2021 09:01:34
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Directory traversal
Description
+ In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
References
+ https://www.drupal.org/sa-core-2021-004
+ https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4f61ca26bf7d4
Notes
CVE-2021-32610 created at 27 Jul 2021 08:58:19