PT-2018-13975 · Hutool · Hutool

Qianxincodesafe

·

Publicado

2018-09-21

·

Atualizado

2018-11-26

·

CVE-2018-17297

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hutool versions prior to 4.1.12
Description The issue allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive, specifically through the unzip function in ZipUtil.java.
Recommendations For versions prior to 4.1.12, update to version 4.1.12 or later to resolve the issue. As a temporary workaround, consider restricting the use of the unzip function in ZipUtil.java to minimize the risk of exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17297
GHSA-RHQ2-2574-78MC

Produtos afetados

Hutool