PT-2022-27298 · Knime · Knime Server

Published

2022-11-24

·

Updated

2022-11-30

·

CVE-2022-44748

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KNIME Server versions 4.3.0 through 4.13.5 KNIME Server versions 4.14.0 through 4.14.2 KNIME Server versions 4.15.0 through 4.15.2
Description A directory traversal vulnerability in the ZIP archive extraction routines can result in arbitrary files being overwritten on the server's file system, also known as 'Zip-Slip'. An attacker can create a KNIME workflow that, when being uploaded, can overwrite arbitrary files that the operating system user running the KNIME Server process has write access to. The user must be authenticated and have permissions to upload files to KNIME Server. This can impact data integrity or cause errors in other software, and can even lead to remote code execution if executable files are being replaced and subsequently executed by the KNIME Server process user.
Recommendations For KNIME Server versions 4.3.0 through 4.13.5, update to version 4.13.6. For KNIME Server versions 4.14.0 through 4.14.2, update to version 4.14.3. For KNIME Server versions 4.15.0 through 4.15.2, update to version 4.15.3.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-44748

Affected Products

Knime Server