QID 980880
QID 980880: Java (maven) Security Update for cn.hutool:hutool-core (GHSA-rhq2-2574-78mc)
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rhq2-2574-78mc for updates pertaining to this vulnerability.
Vendor References
- GHSA-rhq2-2574-78mc -
github.com/advisories/GHSA-rhq2-2574-78mc
CVEs related to QID 980880
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rhq2-2574-78mc | cn.hutool:hutool-all |
|
|
| GHSA-rhq2-2574-78mc | cn.hutool:hutool-core |
|
|
| GHSA-rhq2-2574-78mc | cn.hutool:hutool-parent |
|