joomla/archive
Joomla Archive Package
Activity
- Latest release
- 1y ago
- Total releases
- 33
- Cadence
- ~2 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- unknown
- First release
- Jun 04, 2013
| Version | Released | |
|---|---|---|
4.0.0
major
| ||
3.0.4
patch
| ||
3.0.3
patch
| ||
3.0.2
patch
| ||
3.0.1
patch
| ||
3.0.0
major
| ||
2.0.2
patch
| ||
2.0.1
patch
| ||
1.1.12
patch
| ||
1.1.11
patch
1 CVE
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0-rc
pre
| ||
2.0.0-beta5
pre
| ||
1.1.10
patch
1 CVE
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0-beta4
pre
| ||
1.1.9
patch
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0-beta3
pre
| ||
2.0.0-beta2
pre
| ||
1.1.8
patch
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.7
patch
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0-beta
pre
| ||
1.1.6
patch
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.5
patch
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.4
patch
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.3
patch
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.2
patch
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.1
patch
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.0
minor
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0
initial
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0-beta3
pre
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0-beta2
pre
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0-beta
pre
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0-alpha
pre
2 CVEs
CVE-2022-23793
GHSA-jm67-jh3g-cg3f
BIT-joomla-2022-23793
Mar 31, 2022
Path Traversal within joomla/archive tar class
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
+ 6 more Show less
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
Fixed in
1.1.12
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev
CVE-2021-26028
GHSA-vgwr-773q-7j3c
BIT-joomla-2021-26028
Mar 24, 2021
Path Traversal within joomla/archive zip class
Medium
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 3 more Show less
1.1.7
1.1.8
1.1.9
Fixed in
1.1.10
References
Updated Apr 03, 2025 · Source: OSV.dev |