[MAVEN:GHSA-QCF3-9VMH-XW4R] Improper Limitation of a Pathname to a Restricted Directory in zt-zip

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

Package Affected Version
pkg:maven/org.zeroturnaround/zt-zip < 1.13
Package Fixed Version
pkg:maven/org.zeroturnaround/zt-zip = 1.13
ID
MAVEN:GHSA-QCF3-9VMH-XW4R
Severity
moderate
URL
https://github.com/advisories/GHSA-qcf3-9vmh-xw4r
Published
2022-05-13T01:30:44
(2 years ago)
Modified
2023-01-27T05:02:10
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.zeroturnaround/zt-zip org.zeroturnaround zt-zip < 1.13
Fixed pkg:maven/org.zeroturnaround/zt-zip org.zeroturnaround zt-zip = 1.13
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...