Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1002200

Опубликовано: 05 июн. 2018
Источник: redhat
CVSS3: 7.3

Описание

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

A path traversal vulnerability has been discovered in plexus-archiver when extracting a carefully crafted zip file which holds path traversal file names. A remote attacker could use this vulnerability to write files outside the target directory and overwrite existing files with malicious code or vulnerable configurations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 9plexus-archiverNot affected
Red Hat Enterprise Linux 8plexus-archiverNot affected
Red Hat Fuse 7plexus-archiverNot affected
Red Hat JBoss Fuse Integration Service 2plexus-archiverNot affected
Red Hat OpenStack Platform 9 (Mitaka)opendaylightWill not fix
Red Hat Enterprise Linux 7plexus-archiverFixedRHSA-2018:183612.06.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-maven33-plexus-archiverFixedRHSA-2018:183712.06.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-maven33-plexus-archiverFixedRHSA-2018:183712.06.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-maven33-plexus-archiverFixedRHSA-2018:183712.06.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-maven35-plexus-archiverFixedRHSA-2018:183712.06.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1584392plexus-archiver: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 5.5
nvd
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 5.5
debian
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, all ...

CVSS3: 5.5
github
больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in plexus-archiver

oracle-oval
больше 7 лет назад

ELSA-2018-1836: plexus-archiver security update (IMPORTANT)

7.3 High

CVSS3