GHSA-w8r2-5j8x-x8j6

    Dashboard / Vulnerabilities / GHSA-w8r2-5j8x-x8j6

    GHSA-w8r2-5j8x-x8j6

    Published: 14 May 2022Last Modified: 8 Nov 2023

    Summary: Improper Limitation of a Pathname to a Restricted Directory in WildFly

    Details: WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

    Affected packages

    Package

    Name: org.wildfly.core:wildfly-server

    Purl: pkg:maven/org.wildfly.core/wildfly-server

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -6.0.0.Alpha3

    Affected versions

    1.0.0.Alpha1
    1.0.0.Alpha10
    1.0.0.Alpha11
    1.0.0.Alpha12
    1.0.0.Alpha13
    1.0.0.Alpha14
    1.0.0.Alpha15
    1.0.0.Alpha16
    1.0.0.Alpha17
    1.0.0.Alpha18
    1.0.0.Alpha19
    1.0.0.Alpha2
    1.0.0.Alpha3
    1.0.0.Alpha4
    1.0.0.Alpha5
    1.0.0.Alpha6
    1.0.0.Alpha7
    1.0.0.Alpha8
    1.0.0.Alpha9
    1.0.0.Beta1
    1.0.0.Beta2
    1.0.0.Beta3
    1.0.0.Beta4
    1.0.0.Beta5
    1.0.0.Beta6
    1.0.0.CR1
    1.0.0.CR2
    1.0.0.CR3
    1.0.0.CR4
    1.0.0.CR5
    1.0.0.CR6
    1.0.0.CR7
    1.0.0.Final
    1.0.1.Final
    1.0.2.Final

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-w8r2-5j8x-x8j6 | CVE-DB