Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29141
HistoryJan 26, 2021 - 5:19 a.m.

Zip Slip

2021-01-2605:19:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
zip slip
vulnerability
file writing
oras software

EPSS

0.001

Percentile

35.6%

github.com/deislabs/oras is vulnerable to zip slip. Lack of validation during the extraction of archives or tarballs allows an attacker to write files to arbitrary locations or overwrite arbitrary files via symbolic and hard links in a malicious archive.

EPSS

0.001

Percentile

35.6%