Description
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Remediation
References
https://github.com/looly/hutool/issues/162
Related Vulnerabilities
CVE-2020-13956 Vulnerability in maven package org.apache.httpcomponents.client5:httpclient5
CVE-2020-11020 Vulnerability in maven package org.webjars.npm:faye
CVE-2018-3728 Vulnerability in maven package org.webjars.npm:hoek
CVE-2020-7621 Vulnerability in npm package strong-nginx-controller
CVE-2022-41251 Vulnerability in maven package org.jenkins-ci.plugins:apprenda