If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.13.14CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
<= 3.14.4CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
3.15.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:* | ||
3.15.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:* | ||
3.15.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.