Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8r2-5j8x-x8j6

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Improper Limitation of a Pathname to a Restricted Directory in WildFly

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

Пакеты

Наименование

org.wildfly.core:wildfly-server

maven
Затронутые версииВерсия исправления

<= 6.0.0.Alpha2

6.0.0.Alpha3

EPSS

Процентиль: 55%
0.00325
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.6
redhat
больше 7 лет назад

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

CVSS3: 5.5
nvd
больше 7 лет назад

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

CVSS3: 5.5
debian
больше 7 лет назад

WildFly Core before version 6.0.0.Alpha3 does not properly validate fi ...

EPSS

Процентиль: 55%
0.00325
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22