Description
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Remediation
References
https://github.com/looly/hutool/issues/162
Related Vulnerabilities
CVE-2022-1295 Vulnerability in maven package org.webjars.bower:fullpage
CVE-2020-15999 Vulnerability in maven package org.webjars.npm:electron
CVE-2014-3600 Vulnerability in maven package org.apache.activemq:apache-activemq
CVE-2020-2277 Vulnerability in maven package org.jenkins-ci.plugins:storable-configs-plugin
CVE-2018-1308 Vulnerability in maven package org.apache.solr:solr-dataimporthandler