logo

CVE-2018-1263 org.springframework.integration:spring-integration-zip

Package

Manager: maven
Name: org.springframework.integration:spring-integration-zip
Vulnerable Version: >=0 <1.0.2

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

CVSS v4.0: CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS: 0.01559 pctl0.80788

Details

spring-integration-zip Arbitrary File Write Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

Metadata

Created: 2022-05-13T01:07:04Z
Modified: 2024-04-12T21:24:22Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-87vg-5pgx-pggh/GHSA-87vg-5pgx-pggh.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-87vg-5pgx-pggh
Finding: F063
Auto approve: 1