Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5h3-6h9f-c785

Опубликовано: 27 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’.

A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’.

EPSS

Процентиль: 83%
0.01855
Низкий

8.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
nvd
почти 4 года назад

A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’.

EPSS

Процентиль: 83%
0.01855
Низкий

8.8 High

CVSS3

Дефекты

CWE-22