QID 982976
QID 982976: Java (maven) Security Update for net.sf.mpxj:mpxj (GHSA-p9j6-4pjr-gp48)
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p9j6-4pjr-gp48 for updates pertaining to this vulnerability.
Vendor References
- GHSA-p9j6-4pjr-gp48 -
github.com/advisories/GHSA-p9j6-4pjr-gp48
CVEs related to QID 982976
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p9j6-4pjr-gp48 | net.sf.mpxj:mpxj |
|