Lucene search

K
osvGoogleOSV:CVE-2021-23484
HistoryJan 28, 2022 - 10:15 p.m.

CVE-2021-23484

2022-01-2822:15:09
Google
osv.dev
3

9.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.4%

The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.

9.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.4%

Related for OSV:CVE-2021-23484