Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-48285

Опубликовано: 29 янв. 2023
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.

A flaw was found in the JSZip package. Affected versions of JSZip could allow a remote attacker to traverse directories on the system caused by the failure to sanitize filenames when files are loaded with loadAsync, which makes the library vulnerable to a Zip Slip attack. By extracting files from a specially crafted archive, an attacker could gain access to parts of the file system outside of the target folder, overwrite the executable files, and execute arbitrary commands on the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2openshift-service-mesh/kiali-rhel8Will not fix
OpenShift Service Mesh 2.1openshift-service-mesh/kiali-rhel8Affected
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8mozjs60Not affected
Red Hat Enterprise Linux 9gjsNot affected
Red Hat Enterprise Linux 9polkitNot affected
Red Hat Fuse 7jszipOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-consoleOut of support scope
Red Hat OpenShift Container Platform 4openshift4/ose-consoleWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-23
https://bugzilla.redhat.com/show_bug.cgi?id=2165797jszip: directory traversal via a crafted ZIP archive

EPSS

Процентиль: 64%
0.00463
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 3 лет назад

loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.

CVSS3: 7.3
nvd
около 3 лет назад

loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.

CVSS3: 7.3
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 7.3
debian
около 3 лет назад

loadAsync in JSZip before 3.8.0 allows Directory Traversal via a craft ...

CVSS3: 7.3
github
около 3 лет назад

JSZip contains Path Traversal via loadAsync

EPSS

Процентиль: 64%
0.00463
Низкий

7.3 High

CVSS3