CVE-2025-4435
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
System detected CVE-2025-4435 with a risk of 2.12
System created a ticket for CVE-2025-4435
Everything after this entry will be synced with the external system. The ticket can be found at https://github.com/l3montree-dev/devguard-action/issues/137
System detected CVE-2025-4435 with scanner: container-scanning:test
System removed scanner: container-scanning
System fixed CVE-2025-4435
Reopen this vulnerability
Comment will be synced with https://github.com/l3montree-dev/devguard-action/issues/137
Last calculated at:
Affected component
debian/python3.11