Логотип exploitDog
bind:CVE-2023-46122
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-46122

Количество 3

Количество 3

nvd логотип

CVE-2023-46122

больше 2 лет назад

sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of arbitrary file. This would have potential to overwrite `/root/.ssh/authorized_keys`. Within sbt's main code, `IO.unzip` is used in `pullRemoteCache` task and `Resolvers.remote`; however many projects use `IO.unzip(...)` directly to implement custom tasks. This vulnerability has been patched in version 1.9.7.

CVSS3: 3.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4527-1

около 2 лет назад

Security update for maven, maven-resolver, sbt, xmvn

EPSS: Низкий
github логотип

GHSA-h9mw-grgx-2fhf

больше 2 лет назад

sbt vulnerable to arbitrary file write via archive extraction (Zip Slip)

CVSS3: 3.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-46122

sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of arbitrary file. This would have potential to overwrite `/root/.ssh/authorized_keys`. Within sbt's main code, `IO.unzip` is used in `pullRemoteCache` task and `Resolvers.remote`; however many projects use `IO.unzip(...)` directly to implement custom tasks. This vulnerability has been patched in version 1.9.7.

CVSS3: 3.9
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4527-1

Security update for maven, maven-resolver, sbt, xmvn

0%
Низкий
около 2 лет назад
github логотип
GHSA-h9mw-grgx-2fhf

sbt vulnerable to arbitrary file write via archive extraction (Zip Slip)

CVSS3: 3.9
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу