PT-2022-21208 · Apache · Apache Uima
Huangzhicong
·
Published
2022-11-03
·
Updated
2023-05-22
·
CVE-2022-32287
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache UIMA versions prior to 3.3.0
Description
A relative path traversal vulnerability in the FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. PEAR files should never be installed into a UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.
Recommendations
For versions prior to 3.3.0, consider restricting the installation of PEAR files from untrusted sources to minimize the risk of exploitation. As a temporary workaround, carefully validate the ZIP entry names in PEAR archives before installation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Uima