PT-2022-27334 · Scifio · Scifio
Jonathan Leitschuh
·
Published
2022-12-14
·
Updated
2022-12-16
·
CVE-2022-4493
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
scifio (affected versions not specified)
Description
A critical vulnerability was found in scifio, affecting the function
downloadAndUnpackResource of the file src/test/java/io/scif/util/DefaultSampleFilesService.java of the component ZIP File Handler. The manipulation leads to path traversal. The attack can be launched remotely.Recommendations
To fix this issue, it is recommended to apply a patch. The patch is available at commit
fcb0dbca0ec72b22fe0c9ddc8abc9cb188a0ff31. As a temporary workaround, consider disabling the downloadAndUnpackResource function until a patch is applied. Restrict access to the ZIP File Handler component to minimize the risk of exploitation.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scifio