Codehaus-plexus

Plexus-archiver

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 36.05%
  • Published 25.07.2023 20:15:13
  • Last modified 21.11.2024 08:11:45

Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitra...

Exploit
  • EPSS 1.9%
  • Published 25.07.2018 17:29:00
  • Last modified 21.11.2024 03:40:39

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.