Known vulnerabilities in JSZip
Vendor:
Stuart Knightley
Software:
JSZip
Software CPE:
cpe:2.3:a:stuk:jszip:*:*:*:*:*:*:*:*
Website:
https://stuartk.com/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.9
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU73970 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-48285 |
CWE-22 | Medium | 3.8.0 | 23.03.2023 |
SB2023032314 SB2023032315 SB2023042510 and 22 more |
||
| #VU55579 - Resource exhaustion CVE-2021-23413 |
CWE-400 | Medium | 3.7.0 | 04.08.2021 |
SB2021080408 SB2022081837 SB20230418118 and 4 more |