Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| mixlib-archive(RubyGems) | 0 | 0.4.0 | N/A |
CVSS Metrics