PT-2022-27334 · Scifio · Scifio

·

CVE-2022-4493

·

Published

2022-12-14

·

Updated

2022-12-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions scifio (affected versions not specified)
Description A critical vulnerability was found in scifio, affecting the function downloadAndUnpackResource of the file src/test/java/io/scif/util/DefaultSampleFilesService.java of the component ZIP File Handler. The manipulation leads to path traversal. The attack can be launched remotely.
Recommendations To fix this issue, it is recommended to apply a patch. The patch is available at commit fcb0dbca0ec72b22fe0c9ddc8abc9cb188a0ff31. As a temporary workaround, consider disabling the downloadAndUnpackResource function until a patch is applied. Restrict access to the ZIP File Handler component to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4493
GHSA-CMWM-45MJ-MPG3

Affected Products

Scifio