Description
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Remediation
References
https://github.com/looly/hutool/issues/162
Related Vulnerabilities
CVE-2017-12612 Vulnerability in maven package org.apache.spark:spark-core_2.11
CVE-2021-39133 Vulnerability in maven package org.rundeck:rundeck
CVE-2022-20612 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-7663 Vulnerability in maven package org.webjars.npm:websocket-extensions
CVE-2020-4075 Vulnerability in maven package org.webjars.npm:electron