Lucene search

K
osvGoogleOSV:CVE-2018-10862
HistoryJul 27, 2018 - 2:29 p.m.

CVE-2018-10862

2018-07-2714:29:00
Google
osv.dev
10

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

25.3%

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the ‘Zip Slip’ vulnerability.

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

25.3%