CVE-2022-30333
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- May 07, 2022
- Published Date
- May 09, 2022
- Last Updated
- January 29, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- partial
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-08-09 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/zimbra_unrar_cve_2022_30333.rb | 2025-04-29 11:01:16 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
unrar_cve_2022_30333
Type: metasploit • Created: Unknown
zimbra_unrar_cve_2022_30333
Type: metasploit • Created: Unknown
aslitsecurity/Zimbra-CVE-2022-30333
Type: github • Created: 2022-07-26 13:28:12 UTC • Stars: 7
J0hnbX/CVE-2022-30333
Type: github • Created: 2022-07-22 01:14:29 UTC • Stars: 2
TheL1ghtVn/CVE-2022-30333-PoC
Type: github • Created: 2022-07-05 02:35:12 UTC • Stars: 13