Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpj6-xj62-7c95

Опубликовано: 01 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a ZipFile object.

The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a ZipFile object.

EPSS

Процентиль: 72%
0.00738
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 4 лет назад

The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a ZipFile object.

CVSS3: 5.5
nvd
около 4 лет назад

The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a ZipFile object.

CVSS3: 5.5
debian
около 4 лет назад

The package juce-framework/juce before 6.1.5 are vulnerable to Arbitra ...

EPSS

Процентиль: 72%
0.00738
Низкий

Дефекты

CWE-22