Tags: web symlink race-condition 

Rating:

**tl;dr**

+ Zip Slip Vulnerability + YAML Deserialization Attack + Race Condition
+ Unintended Solution: Upload symlink leading to arbitarary file reads

For full writeup, click [here](https://blog.bi0s.in/2020/06/07/Web/Defenit20-TarAnalyzer/)

Original writeup (https://blog.bi0s.in/2020/06/07/Web/Defenit20-TarAnalyzer/).