Path traversal in plexus-archiver - CVE-2023-37460
Published: September 19, 2023
Vulnerability identifier: #VU80879
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-37460
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
plexus-archiver
Migration Toolkit for Runtimes
IBM Cloud Pak for Business Automation
Amazon Linux AMI
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
openEuler
plexus-archiver (Red Hat package)
plexus-archiver
plexus-archiver-javadoc
Operational Decision Manager
Migration Toolkit for Runtimes
IBM Cloud Pak for Business Automation
Amazon Linux AMI
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
openEuler
plexus-archiver (Red Hat package)
plexus-archiver
plexus-archiver-javadoc
Operational Decision Manager
How to mitigate CVE-2023-37460
Install update from vendor's website.
plexus-archiver - update to 4.8.0
plexus-archiver (Red Hat package) - update to 2.4.2-6.el7_9
plexus-archiver - update to 2.4.2-6.0.1
plexus-archiver-javadoc - update to 2.4.2-6.0.1
plexus-archiver - addressed in versions 3.6.0-4, 4.2.6-2, 4.2.7-2
plexus-archiver - update to 4.2.7-4
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 41, 8.11.0.1 Interim fix 21, 8.11.1 Interim fix 10, 8.12.0 Interim fix 2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
plexus-archiver (Red Hat package) - update to 2.4.2-6.el7_9
plexus-archiver - update to 2.4.2-6.0.1
plexus-archiver-javadoc - update to 2.4.2-6.0.1
plexus-archiver - addressed in versions 3.6.0-4, 4.2.6-2, 4.2.7-2
plexus-archiver - update to 4.2.7-4
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 41, 8.11.0.1 Interim fix 21, 8.11.1 Interim fix 10, 8.12.0 Interim fix 2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM Operational Decision Manager
- Red Hat Migration Toolkit for Runtimes update for plexus-archiver
- Red Hat Enterprise Linux 7 update for plexus-archiver
- Amazon Linux AMI update for javapackages-bootstrap
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Amazon Linux AMI update for plexus-archiver
- Anolis OS update for plexus-archiver
- openEuler 22.03 LTS SP4 update for plexus-archiver
- openEuler 20.03 LTS SP4 update for plexus-archiver
- openEuler 24.03 LTS SP1 update for plexus-archiver
- openEuler 24.03 LTS update for plexus-archiver
- openEuler 22.03 LTS SP3 update for plexus-archiver
- openEuler 24.03 LTS SP2 update for plexus-archiver