MEDIUM5.5
GHSA-fxh6-w476-hgr4
Directory Traversal in SharpCompress
Quick fix
GHSA-fxh6-w476-hgr4 — SharpCompress: upgrade to the fixed version with the command below.
dotnet add package SharpCompress --version 0.21.0Details
SharpCompress prior to version 0.21 is vulnerable to path traversal issue in archive extraction.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/SharpCompress
Introduced in:
0Fixed in: 0.21.0Fix
dotnet add package SharpCompress --version 0.21.0References
- https://nvd.nist.gov/vuln/detail/CVE-2018-1002206[ADVISORY]
- https://github.com/adamhathcock/sharpcompress/pull/374[WEB]
- https://github.com/adamhathcock/sharpcompress/commit/42b1205fb435de523e6ef8ac5b7bafbe712997f6[WEB]
- https://github.com/adamhathcock/sharpcompress/commit/80ceb1c375fdb1b4ffba16528c99089e804ce61f[WEB]
- https://github.com/snyk/zip-slip-vulnerability[WEB]
- https://snyk.io/research/zip-slip-vulnerability[WEB]
- https://snyk.io/vuln/SNYK-DOTNET-SHARPCOMPRESS-60246[WEB]