Path traversal in Zipper - #VU25765

 

Path traversal in Zipper - #VU25765

Published: March 4, 2020


Vulnerability identifier: #VU25765
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error of filenames when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system, leading to to arbitrary file write via Archive Extraction (Zip Slip).


Affected software

Zipper

Remediation

Install update from vendor's website.

Zipper - update to 1.0.3

External References

Related Security Bulletins