Versions of tar
prior to 2.0.0 are affected by an arbitrary file write vulnerability. The vulnerability occurs because tar
does not verify that extracted symbolic links to not resolve to targets outside of the extraction root directory.
Update to version 2.0.0 or later
{ "nvd_published_at": null, "github_reviewed_at": "2020-06-16T21:37:06Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-59" ] }