Moderate severityNVD Advisory· Published Jul 25, 2018· Updated Aug 5, 2024
CVE-2018-1002202
CVE-2018-1002202
Description
zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.lingala.zip4j:zip4jMaven | < 1.3.3 | 1.3.3 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-2rpm-4x8c-pvqgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-1002202ghsaADVISORY
- snyk.io/research/zip-slip-vulnerabilityghsax_refsource_MISCWEB
- snyk.io/vuln/SNYK-JAVA-NETLINGALAZIP4J-31679ghsax_refsource_MISCWEB
- support.hpe.com/hpsc/doc/public/displayghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.