Vulnerability Description
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Py7Zr Project | Py7Zr | < 0.20.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/170127/py7zr-0.20.0-Directory-Traversal.htmExploitThird Party AdvisoryVDB Entry
- https://github.com/miurahr/py7zr/commit/1bb43f17515c7f69673a1c88ab9cc72a7bbef406PatchThird Party Advisory
- https://lessonsec.com/cve/cve-2022-44900/ExploitThird Party Advisory
- http://packetstormsecurity.com/files/170127/py7zr-0.20.0-Directory-Traversal.htmExploitThird Party AdvisoryVDB Entry
- https://github.com/miurahr/py7zr/commit/1bb43f17515c7f69673a1c88ab9cc72a7bbef406PatchThird Party Advisory
- https://lessonsec.com/cve/cve-2022-44900/ExploitThird Party Advisory
FAQ
What is CVE-2022-44900?
CVE-2022-44900 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file...
How severe is CVE-2022-44900?
CVE-2022-44900 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-44900?
Check the references section above for vendor advisories and patch information. Affected products include: Py7Zr Project Py7Zr.