CVE-2024-21542 Information
Dec 11, 2024
cve
Description
Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.
Reference
https://github.com/spotify/luigi/commit/b5d1b965ead7d9f777a3216369b5baf23ec08999 https://github.com/spotify/luigi/issues/3301 https://github.com/spotify/luigi/releases/tag/v3.6.0 https://security.snyk.io/vuln/SNYK-PYTHON-LUIGI-7830489
Share on: