Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10862

Опубликовано: 27 июл. 2018
Источник: debian
EPSS Низкий

Описание

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wildflyitppackage

EPSS

Процентиль: 67%
0.01262
Низкий

Связанные уязвимости

CVSS3: 7.6
redhat
около 8 лет назад

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

CVSS3: 5.5
nvd
около 8 лет назад

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

CVSS3: 5.5
github
больше 4 лет назад

Improper Limitation of a Pathname to a Restricted Directory in WildFly

EPSS

Процентиль: 67%
0.01262
Низкий