Описание
MITM based Zip Slip in org.hl7.fhir.publisher:org.hl7.fhir.publisher
Impact
MITM can enable Zip-Slip.
Vulnerability
Vulnerability 1: Publisher.java
There is no validation that the zip file being unpacked has entries that are not maliciously writing outside of the intended destination directory.
Vulnerability 2: WebSourceProvider.java
There is a check for malicious zip entries here, but it is not covered by test cases and could potentially be reverted in future changes.
Vulnerability 3: ZipFetcher.java
This retains the path for Zip files in FetchedFile entries, which could later be used to output malicious entries to another compressed file or file system.
Vulnerability 4: IGPack2NpmConvertor.java
The loadZip method retains the path for entries in the zip file, which could later be used to output malicious entries to another compressed file or file system.
Пакеты
org.hl7.fhir.publisher:org.hl7.fhir.publisher
< 1.2.30
1.2.30
9.1 Critical
CVSS3
9.1 Critical
CVSS3