CVE-2022-30333 — RARLAB UnRAR Directory Traversal Vulnerability
2022-08-09 • CISA Known Exploited Vulnerability
[event] RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | RARLAB |
| Product | UnRAR |
| CWE | CWE-22, CWE-59 |
| CVE ID | CVE-2022-30333 |
| Date Added | 2022-08-09 |
| Due Date | 2022-08-30 |
| Ransomware Campaign | Known — this vulnerability has been leveraged in ransomware campaigns |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2022-08-30