PT-2022-6761 · Jszip+1 · Jszip+1

Mccaulay Hudson

·

Published

2022-03-30

·

Updated

2024-08-01

·

CVE-2022-48285

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JSZip versions prior to 3.8.0
Description The issue is related to the loadAsync function in JSZip, which allows directory traversal via a crafted ZIP archive. This can be exploited by a remote attacker to write arbitrary files and execute arbitrary commands using a specially crafted malicious ZIP archive.
Recommendations For versions prior to 3.8.0, update to version 3.8.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the loadAsync function until a patch is available. Avoid using the loadAsync function with untrusted ZIP archives until the issue is resolved.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

AZL-38236
AZL-57076
BDU:2023-04192
CVE-2022-48285
GHSA-36FH-84J7-CV5H

Affected Products

Debian
Jszip