Description
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Remediation
References
https://github.com/looly/hutool/issues/162
Related Vulnerabilities
CVE-2023-30525 Vulnerability in maven package org.jenkins-ci.plugins:reportportal
CVE-2018-20822 Vulnerability in npm package node-sass
CVE-2017-7556 Vulnerability in maven package io.hawt:project
CVE-2023-26109 Vulnerability in npm package node-bluetooth-serial-port
CVE-2017-12612 Vulnerability in maven package org.apache.spark:spark-core_2.10