Description
core/api/datasets/internal/actions/Explode.java in the Dataset API in DKPro Core through 1.10.0 allows Directory Traversal, resulting in the overwrite of local files with the contents of an archive.
Remediation
References
https://github.com/dkpro/dkpro-core/issues/1325
Related Vulnerabilities
CVE-2021-21179 Vulnerability in npm package electron
CVE-2023-32313 Vulnerability in npm package vm2
CVE-2022-31070 Vulnerability in npm package @finastra/nestjs-proxy
CVE-2021-29425 Vulnerability in maven package commons-io:commons-io
CVE-2020-6427 Vulnerability in maven package org.webjars.npm:electron