Back to CVE Lookup
CVE-2022-30333
HIGH - CVSS 7.5CWE-22
Published: 5/9/2022
Modified: 11/3/2025
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
Vulnerability Summary
CVSS v3 Score
7.5HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2 Score
5
AV:N/AC:L/Au:N/C:N/I:P/A:N