Description
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Remediation
References
https://github.com/looly/hutool/issues/162
Related Vulnerabilities
CVE-2023-49371 Vulnerability in maven package com.ruoyi:ruoyi
CVE-2023-47320 Vulnerability in maven package org.silverpeas.core:silverpeas-core-war
CVE-2022-25901 Vulnerability in npm package cookiejar
CVE-2021-26540 Vulnerability in npm package sanitize-html
CVE-2022-3783 Vulnerability in npm package node-red-dashboard