QID 995492

Date Published: 2023-10-03

QID 995492: Java (Maven) Security Update for org.codehaus.plexus:plexus-utils (GHSA-g6ph-x5wf-g337)

A flaw was found in plexus-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with dot-dot-slash (../) sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-g6ph-x5wf-g337 for updates and patch information.
    Vendor References

    CVEs related to QID 995492

    Software Advisories
    Advisory ID Software Component Link
    GHSA-g6ph-x5wf-g337 org.codehaus.plexus:plexus-utils URL Logo github.com/advisories/GHSA-g6ph-x5wf-g337