Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7516
HistorySep 24, 2018 - 2:00 a.m.

Directory Traversal

2018-09-2402:00:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.001

Percentile

51.2%

hutool-core is vulnerable to directory traversal. There is a lack of validation in the filenme when a ZIP archive is unzipped, which would allow remote attackers to overwrite arbitrary files using the ../ characters in a filename within the ZIP archive.

EPSS

0.001

Percentile

51.2%