clearml is vulnerable to Improper Link Resolution Before File Access ('Link Following')
60
Medium Risk
Affected versions of this package are vulnerable to path traversal when extracting tar archives containing malicious symlinks, as the safe_extract function checks directory traversal for regular files but does not properly validate symbolic links, allowing an attacker to write arbitrary files outside the target directory by including specially crafted symlinks in the archive.
You are affected if you are using a version that falls within the vulnerable range.
clearml is vulnerable to Improper Link Resolution Before File Access ('Link Following') in versions 1.8.0 - 2.0.1.
Upgrade the clearml library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant