Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7v39-2hx7-7c43

Опубликовано: 12 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip

An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.

Пакеты

Наименование

github.com/weaviate/weaviate

go
Затронутые версииВерсия исправления

< 1.30.20

1.30.20

Наименование

github.com/weaviate/weaviate

go
Затронутые версииВерсия исправления

>= 1.31.0-rc.0, < 1.31.19

1.31.19

Наименование

github.com/weaviate/weaviate

go
Затронутые версииВерсия исправления

>= 1.32.0-rc.0, < 1.32.16

1.32.16

Наименование

github.com/weaviate/weaviate

go
Затронутые версииВерсия исправления

>= 1.33.0-rc.0, < 1.33.4

1.33.4

EPSS

Процентиль: 53%
0.00304
Низкий

8.7 High

CVSS4

Дефекты

CWE-22
CWE-61

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 месяцев назад

An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absolute path (e.g., /etc/...) or use parent directory traversal (../../..) to escape the restore root when a backup is restored, potentially creating or overwriting files in arbitrary locations within the application's privilege scope.

EPSS

Процентиль: 53%
0.00304
Низкий

8.7 High

CVSS4

Дефекты

CWE-22
CWE-61