GHSA-w8r2-5j8x-x8j6
Dashboard / Vulnerabilities / GHSA-w8r2-5j8x-x8j6
Summary: Improper Limitation of a Pathname to a Restricted Directory in WildFly
Details: WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-10862, https://access.redhat.com/errata/RHSA-2018:2276, https://access.redhat.com/errata/RHSA-2018:2277, https://access.redhat.com/errata/RHSA-2018:2279, https://access.redhat.com/errata/RHSA-2018:2423, https://access.redhat.com/errata/RHSA-2018:2424, https://access.redhat.com/errata/RHSA-2018:2425, https://access.redhat.com/errata/RHSA-2018:2428, https://access.redhat.com/errata/RHSA-2018:2643, https://access.redhat.com/errata/RHSA-2019:0877, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10862, https://snyk.io/research/zip-slip-vulnerability
Affected packages
Package
Name: org.wildfly.core:wildfly-server
Purl: pkg:maven/org.wildfly.core/wildfly-server
Affected ranges
Type: ECOSYSTEM
Events:
