CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Codehaus Plexus 1Plexus Archiver Nov 21, 2024 Jul 25, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an ar...Show more |
3Codehaus Plexus DebianRedhat5Debian Linux Enterprise LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Jul 25, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is...Show more |