CVE-2018-1263 – org.springframework.integration:spring-integration-zip
Package
Manager: maven
Name: org.springframework.integration:spring-integration-zip
Vulnerable Version: >=0 <1.0.2
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.01559 pctl0.80788
Details
spring-integration-zip Arbitrary File Write Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
Metadata
Created: 2022-05-13T01:07:04Z
Modified: 2024-04-12T21:24:22Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-87vg-5pgx-pggh/GHSA-87vg-5pgx-pggh.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-87vg-5pgx-pggh
Finding: F063
Auto approve: 1