Логотип exploitDog
bind:CVE-2018-1263
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-1263

Количество 2

Количество 2

nvd логотип

CVE-2018-1263

больше 7 лет назад

Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-87vg-5pgx-pggh

больше 3 лет назад

spring-integration-zip Arbitrary File Write

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-1263

Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

CVSS3: 4.7
1%
Низкий
больше 7 лет назад
github логотип
GHSA-87vg-5pgx-pggh

spring-integration-zip Arbitrary File Write

CVSS3: 4.7
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу