Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS13OHIyLTVqOHgteDhqNs4AATig

Improper Limitation of a Pathname to a Restricted Directory in WildFly

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

Permalink: https://github.com/advisories/GHSA-w8r2-5j8x-x8j6
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13OHIyLTVqOHgteDhqNs4AATig
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: over 1 year ago


CVSS Score: 5.5
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Identifiers: GHSA-w8r2-5j8x-x8j6, CVE-2018-10862
References: Blast Radius: 12.9

Affected Packages

maven:org.wildfly.core:wildfly-server
Dependent packages: 355
Dependent repositories: 223
Downloads:
Affected Version Ranges: <= 6.0.0.Alpha2
Fixed in: 6.0.0.Alpha3
All affected versions:
All unaffected versions: