PT-2022-21208 · Apache · Apache Uima

Huangzhicong

·

Published

2022-11-03

·

Updated

2023-05-22

·

CVE-2022-32287

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache UIMA versions prior to 3.3.0
Description A relative path traversal vulnerability in the FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. PEAR files should never be installed into a UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.
Recommendations For versions prior to 3.3.0, consider restricting the installation of PEAR files from untrusted sources to minimize the risk of exploitation. As a temporary workaround, carefully validate the ZIP entry names in PEAR archives before installation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-32287
GHSA-XGQR-5WQW-9FPV

Affected Products

Apache Uima