Path traversal in sbt and io - CVE-2023-46122
Published: November 22, 2023
sbt
io
Scala sbt
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick the victim to open a specially crafted zip or JAR file and overwrite arbitrary files on the system, such as /root/.ssh/authorized_keys, which can result in full system compromise.