5.8
CVSSv2

CVE-2018-1002202

Published: 25/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 517
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

zip4j prior to 1.3.3 is vulnerable to directory traversal, allowing malicious users to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zip4j project zip4j

Vendor Advisories

zip4j before 133 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a / (dot dot slash) in a Zip archive entry that is mishandled during extraction This vulnerability is also known as 'Zip-Slip' ...