Описание
pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.
Ссылки
- Third Party Advisory
- Patch
- Issue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.14.1 (исключая)
cpe:2.3:a:pf4j_project:pf4j:*:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00287
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.5
ubuntu
14 дней назад
pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.
CVSS3: 7.5
debian
14 дней назад
pf4j before 20c2f80 has a path traversal vulnerability in the extract( ...
github
14 дней назад
pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names
EPSS
Процентиль: 52%
0.00287
Низкий
7.5 High
CVSS3
Дефекты
CWE-22