CVE-2025-4435

HIGH7.5EPSS 0.54%

Tarfile extracts filtered members when errorlevel=0

發布日:2025/6/3修改日:2026/4/28

描述

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

受影響套件(5)

  • Bitnami/libpythonfrom 0, < 3.9.23, >= 3.10.0, < 3.10.18, >= 3.11.0, < 3.11.13, >= 3.12.0, < 3.12.11, >= 3.13.0, < 3.13.4
  • Bitnami/pythonfrom 0, < 3.9.23, >= 3.10.0, < 3.10.18, >= 3.11.0, < 3.11.13, >= 3.12.0, < 3.12.11, >= 3.13.0, < 3.13.4
  • Bitnami/python-minfrom 0, < 3.9.23, >= 3.10.0, < 3.10.18, >= 3.11.0, < 3.11.13, >= 3.12.0, < 3.12.11, >= 3.13.0, < 3.13.4
  • Debian/pypy3from 0
  • Debian/python3.13from 0, < 3.13.4-1

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

參考連結(13)