Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5458-7hh9-v7p4

Опубликовано: 25 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names

pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.

Пакеты

Наименование

org.pf4j:pf4j

maven
Затронутые версииВерсия исправления

< 3.14.1

3.14.1

EPSS

Процентиль: 52%
0.00287
Низкий

8.7 High

CVSS4

Дефекты

CWE-22
CWE-23

Связанные уязвимости

CVSS3: 7.5
ubuntu
14 дней назад

pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.

CVSS3: 7.5
nvd
14 дней назад

pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.

CVSS3: 7.5
debian
14 дней назад

pf4j before 20c2f80 has a path traversal vulnerability in the extract( ...

EPSS

Процентиль: 52%
0.00287
Низкий

8.7 High

CVSS4

Дефекты

CWE-22
CWE-23