A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.
                
            References
                    | Link | Resource | 
|---|---|
| http://packetstormsecurity.com/files/170127/py7zr-0.20.0-Directory-Traversal.html | Exploit Third Party Advisory VDB Entry | 
| https://github.com/miurahr/py7zr/commit/1bb43f17515c7f69673a1c88ab9cc72a7bbef406 | Patch Third Party Advisory | 
| https://lessonsec.com/cve/cve-2022-44900/ | Exploit Third Party Advisory | 
| http://packetstormsecurity.com/files/170127/py7zr-0.20.0-Directory-Traversal.html | Exploit Third Party Advisory VDB Entry | 
| https://github.com/miurahr/py7zr/commit/1bb43f17515c7f69673a1c88ab9cc72a7bbef406 | Patch Third Party Advisory | 
| https://lessonsec.com/cve/cve-2022-44900/ | Exploit Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 07:28
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-12-06 20:15
Updated : 2025-04-23 15:15
NVD link : CVE-2022-44900
Mitre link : CVE-2022-44900
CVE.ORG link : CVE-2022-44900
JSON object : View
Products Affected
                py7zr_project
- py7zr
 
CWE
                
                    
                        
                        CWE-22
                        
            Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
