Headline
CVE-2022-36066: SECURITY: Prevent arbitrary file write when decompressing files by CvX · Pull Request #18421 · discourse/discourse
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the stable
branch and prior to 2.9.0.beta10 on the beta
and tests-passed
branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and trigger remote code execution. The problem is patched in version 2.8.9 on the stable
branch and version 2.9.0.beta10 on the beta
and tests-passed
branches. There are no known workarounds.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
Pick a username
Email Address
Password
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account