When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
{ "cpes": [ "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*" ], "severity": "High" }