Description
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5534 | WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability. |
Github GHSA |
GHSA-w8r2-5j8x-x8j6 | Improper Limitation of a Pathname to a Restricted Directory in WildFly |
References
History
Fri, 23 Aug 2024 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7 |
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T07:46:47.486Z
Reserved: 2018-05-09T00:00:00.000Z
Link: CVE-2018-10862
No data.
Status : Modified
Published: 2018-07-27T14:29:00.300
Modified: 2024-11-21T03:42:10.053
Link: CVE-2018-10862
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA