We found results for “”
CVE-2023-46122
Good to know:
Date: October 23, 2023
sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, "IO.unzip" allows writing of arbitrary file. This would have potential to overwrite "/root/.ssh/authorized_keys". Within sbt's main code, "IO.unzip" is used in "pullRemoteCache" task and "Resolvers.remote"; however many projects use "IO.unzip(...)" directly to implement custom tasks. This vulnerability has been patched in version 1.9.7.
Language: SCALA
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22Top Fix
Upgrade Version
Upgrade to version org.scala-sbt:io_3:1.9.7;org.scala-sbt:io_2.12:1.9.7;org.scala-sbt:io_2.13:1.9.7;org.scala-sbt:sbt:1.9.7
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | LOCAL |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | REQUIRED |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | LOW |
Vulnerabilities
Projects
Contact Us


