Description
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Remediation
References
https://github.com/looly/hutool/issues/162
Related Vulnerabilities
CVE-2023-40814 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2021-34428 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2019-16552 Vulnerability in maven package com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger
CVE-2019-10319 Vulnerability in maven package org.jenkins-ci.plugins:pam-auth
CVE-2022-39382 Vulnerability in npm package @keystone-6/core