Description
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Remediation
References
https://github.com/looly/hutool/issues/162
Related Vulnerabilities
CVE-2019-1003094 Vulnerability in maven package org.jenkins-ci.plugins:open-stf
CVE-2020-36180 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2015-6748 Vulnerability in maven package org.jsoup:jsoup
CVE-2022-33987 Vulnerability in maven package org.webjars.npm:got
CVE-2019-5448 Vulnerability in maven package org.webjars.npm:yarn