漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using relative pathnames. This issue is addressed in container 0.8.0 and containerization 0.21.0.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Containerization 安全漏洞
Vulnerability Description
Containerization是Apple开源的一个Swift容器包。 Containerization存在安全漏洞,该漏洞源于提取存档成员前未进行路径名验证,可能导致文件被提取到任意用户可写位置。
CVSS Information
N/A
Vulnerability Type
N/A