We found results for “”
WS-2019-0164
Good to know:
Date: January 16, 2019
decompress-zip 0.2.x before 0.2.2 and 0.3.x before 0.3.2 has a Zip-Slip vulnerability, an arbitrary file write vulnerability.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22Top Fix
Upgrade Version
Upgrade to version adrexia/silverstripe-pure - no_fix;Ncapsulate.Bower - no_fix;dreamfactory/df-api-docs-ui - 1.1.0;MIDIator.WebClient - 1.0.105;Bower - no_fix;decompress-zip - 0.2.2;decompress-zip - 0.3.2;NativeScript.Sidekick.Standalone.Shell - no_fix;adrexia/silverstripe-gumby-theme - 2;yuan1994/wechat_web_devtools - 0.7.0;yuan1994/wechat_web_devtools - 0.15.152901-core;org.webjars.bower:jsonpath-object-transform:no_fix;org.webjars.npm:bower:1.8.12;org.webjars.npm:decompress-zip:no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


