PT-2022-17642 · Unknown · Com.Diffplug.Gradle:Goomph

Jonathan Leitschuh

·

Published

2022-09-11

·

Updated

2022-09-16

·

CVE-2022-26049

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions com.diffplug.gradle:goomph versions prior to 3.37.2
Description This issue allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an attacker to achieve remote code execution on a target system by exploiting this issue. The only file that Goomph extracts is the p2 bootstrapper and eclipse metadata files hosted at eclipse.org, which are not malicious, so the only way this issue could have affected users is if they had set a custom bootstrap zip, and that zip was malicious.
Recommendations For versions prior to 3.37.2, update to version 3.37.2 or later to resolve the issue. As a temporary workaround, consider avoiding the use of custom bootstrap zips to minimize the risk of exploitation. Restrict access to arbitrary directories to prevent potential remote code execution.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-26049
GHSA-P2F7-9CV7-JJF6

Affected Products

Com.Diffplug.Gradle:Goomph