Lucene search

K

Juce Security Vulnerabilities

cve
cve

CVE-2021-23521

This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containing a symbolic link. When extracted, the symbolic link is followed outside of the target dir allowing writing arbitrary files on the target host. In...

7.8CVSS

7.8AI Score

0.001EPSS

2022-01-31 11:15 AM
39
cve
cve

CVE-2021-23520

The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a ZipFile...

9.8CVSS

9.3AI Score

0.003EPSS

2022-01-31 11:15 AM
23