MEDIUM
GHSA-vgwr-773q-7j3c
Path Traversal within joomla/archive zip class
Quick fix
GHSA-vgwr-773q-7j3c — joomla/archive: upgrade to the fixed version with the command below.
composer require joomla/archive:^1.1.10Details
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-26028[ADVISORY]
- https://github.com/joomla-framework/archive/commit/32c9009a1020d16bc1060c0d06339898b697cf2c[WEB]
- https://developer.joomla.org/security-centre/848-20210308-core-path-traversal-within-joomla-archive-zip-class.html[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/joomla/archive/CVE-2021-26028.yaml[WEB]