Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

7He6Uzzer

#25923of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2022-9401
9.8
2022-01-28
Zip-Local · Zip-Local · CVE-2021-23484
**Name of the Vulnerable Software and Affected Versions** zip-local versions prior to 0.3.5 **Description** The issue allows for Arbitrary File Write via Archive Extraction, also known as Zip Slip, which can lead to the extraction of a crafted file outside the intended extraction directory. This can potentially cause security problems. **Recommendations** For versions prior to 0.3.5, update to version 0.3.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of archive extraction functions until a patch is applied.