QID 981786
QID 981786: Java (maven) Security Update for de.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl (GHSA-23gj-368h-92pq)
core/api/datasets/internal/actions/Explode.java in the Dataset API in DKPro Core through 1.10.0 allows Directory Traversal, resulting in the overwrite of local files with the contents of an archive.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-23gj-368h-92pq for updates pertaining to this vulnerability.
Vendor References
- GHSA-23gj-368h-92pq -
github.com/advisories/GHSA-23gj-368h-92pq
CVEs related to QID 981786
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-23gj-368h-92pq | de.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl |
|