{ "schema_version": "1.4.0", "id": "GHSA-h4mr-p94x-gf79", "modified": "2025-01-29T18:31:05Z", "published": "2022-05-10T00:00:21Z", "aliases": [ "CVE-2022-30333" ], "details": "RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30333" }, { "type": "WEB", "url": "https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day" }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00022.html" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/202309-04" }, { "type": "WEB", "url": "https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz" }, { "type": "WEB", "url": "https://www.rarlab.com/rar_add.htm" }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.html" } ], "database_specific": { "cwe_ids": [ "CWE-22" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2022-05-09T08:15:00Z" } }