PT-2021-10850 · Kuba · Kuba

Jiahao42

·

Published

2021-08-10

·

Updated

2021-08-17

·

CVE-2020-23172

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kuba versions all
Description A vulnerability allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.
Recommendations For all versions, consider restricting the handling of .zip archives until a proper fix is applied, and ensure that file paths are properly validated to prevent arbitrary file overwrites.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23172

Affected Products

Kuba