CVE-2022-30333

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-30333
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-30333.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-30333
Downstream
Related
Published
2022-05-09T08:15:06Z
Modified
2025-08-09T19:01:27Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

References

Affected packages