Vigilance.fr - Rust astral-tokio-tar: directory traversal via Entry::unpack_in_raw(), analyzed on 03/10/2025

An attacker can traverse directories of Rust astral-tokio-tar, via Entry::unpack_in_raw(), in order to write a file outside the service root path.

Espace publicitaire · 300×250