rpm package
opensuse/python-unearth&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/python-unearth&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-73030 | Hig | 8.1 | < 0.18.3-1.1 | 0.18.3-1.1 | Aug 10, 2026 | unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives | |
| CVE-2023-45805 | Hig | 7.8 | < 0.18.3-1.1 | 0.18.3-1.1 | Oct 20, 2023 | pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source project to appear to depend on a trusted PyPI project, but actually install another p |
- affected < 0.18.3-1.1fixed 0.18.3-1.1
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives
- affected < 0.18.3-1.1fixed 0.18.3-1.1
pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source project to appear to depend on a trusted PyPI project, but actually install another p