Description
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Remediation
References
https://github.com/looly/hutool/issues/162
Related Vulnerabilities
CVE-2021-21120 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-36944 Vulnerability in maven package org.scala-lang:scala-library
CVE-2022-39299 Vulnerability in npm package @node-saml/node-saml
CVE-2015-8854 Vulnerability in maven package org.webjars:marked
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap