Tarfile path traversal bug from 2007 still present in 350k open source repos | The Daily Swig
Read full post . . . or http://www.go-que.com/tarfile-path-traversal-bug-from-2007-still-present-in-350k-open-source-repos-the-daily-swig
Read full post . . . or https://www.google.com/url?rct=j&sa=t&url=https://portswigger.net/daily-swig/tarfile-path-traversal-bug-from-2007-still-present-in-350k-open-source-repos&ct=ga&cd=CAIyGjgzMjVmMTg3YzNmN2FkZTk6Y29tOmVuOlVT&usg=AOvVaw12bfmaihRANNFhMqRjMVNR
Having “stumbled across” the unpatched issue while investigating an unrelated vulnerability, they initially thought the flaw was a new zero-day bug … https://www.google.com/url?rct=j&sa=t&url=https://portswigger.net/daily-swig/tarfile-path-traversal-bug-from-2007-still-present-in-350k-open-source-repos&ct=ga&cd=CAIyGjgzMjVmMTg3YzNmN2FkZTk6Y29tOmVuOlVT&usg=AOvVaw12bfmaihRANNFhMqRjMVNR