Path Traversal in Spring-integration-zip
Moderate severity
GitHub Reviewed
Published
Mar 18, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
< 1.0.4
Patched versions
1.0.4
Description
Published by the National Vulnerability Database
Mar 1, 2021
Reviewed
Mar 22, 2021
Published to the GitHub Advisory Database
Mar 18, 2022
Last updated
Feb 1, 2023
Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
References