{ "schema_version": "1.4.0", "id": "GHSA-2vjx-96pr-9r8r", "modified": "2022-03-02T00:00:37Z", "published": "2022-02-19T00:00:54Z", "aliases": [ "CVE-2022-25358" ], "details": "A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25358" }, { "type": "WEB", "url": "https://github.com/mario-goulart/awful-salmonella-tar/commit/f705c881769b7610745cd4b4d8ae8b41b3f4f845" }, { "type": "WEB", "url": "https://wiki.call-cc.org/eggref/5/awful-salmonella-tar" } ], "database_specific": { "cwe_ids": [ "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2022-02-18T22:15:00Z" } }