Unknown · Cauldron Cbang · CVE-2023-31483
**Name of the Vulnerable Software and Affected Versions**
Cauldron cbang versions prior to bastet-v8.1.17
**Description**
The issue allows for directory traversal during extraction, enabling an attacker to create or write to files outside the current directory by using a crafted tar archive. This is due to a flaw in the tar/TarFileReader.cpp component.
**Recommendations**
For versions prior to bastet-v8.1.17, update to bastet-v8.1.17 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted tar archives until the update is applied.