VYPR

Plexus Archiver

by Apache

Source repositories

CVEs (2)

  • CVE-2023-37460HigJul 25, 2023
    risk 0.46cvss 8.1epss 0.02

    Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly…

  • CVE-2018-1002200MedJul 25, 2018
    risk 0.30cvss 5.5epss 0.13

    plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.