VYPR
High severityNVD Advisory· Published Mar 30, 2022· Updated Feb 25, 2026

[20220301] - Core - Zip Slip within the Tar extractor

CVE-2022-23793

Description

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
joomla/archivePackagist
< 1.1.121.1.12
joomla/archivePackagist
>= 2.0.0, < 2.0.12.0.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.