High severity7.8NVD Advisory· Published Jun 7, 2018· Updated Jun 17, 2026
CVE-2018-12036
CVE-2018-12036
Description
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.owasp:dependency-check-mavenMaven | < 3.2.0 | 3.2.0 |
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-hcwx-7q5v-vc67ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-12036ghsaADVISORY
- github.com/jeremylong/DependencyCheck/blob/master/RELEASE_NOTES.mdnvdRelease NotesWEB
News mentions
0No linked articles in our index yet.