CVE-2024-21542 Information

Description

Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.

Reference

https://github.com/spotify/luigi/commit/b5d1b965ead7d9f777a3216369b5baf23ec08999 https://github.com/spotify/luigi/issues/3301 https://github.com/spotify/luigi/releases/tag/v3.6.0 https://security.snyk.io/vuln/SNYK-PYTHON-LUIGI-7830489

Share on: