CVE-2021-26028: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
References
- developer.joomla.org/security-centre/848-20210308-core-path-traversal-within-joomla-archive-zip-class.html
- github.com/FriendsOfPHP/security-advisories/blob/master/joomla/archive/CVE-2021-26028.yaml
- github.com/advisories/GHSA-vgwr-773q-7j3c
- github.com/joomla-framework/archive/commit/32c9009a1020d16bc1060c0d06339898b697cf2c
- nvd.nist.gov/vuln/detail/CVE-2021-26028
Detect and mitigate CVE-2021-26028 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →