Description
Users with write permissions to a repository can delete arbitrary directories.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/15/3
https://lists.apache.org/thread/1odl4p85r96n27k577jk6ftrp19xfc27
Related Vulnerabilities
CVE-2021-21119 Vulnerability in maven package org.webjars.npm:electron
CVE-2019-12384 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-33891 Vulnerability in maven package org.apache.spark:spark-core_2.13
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-mysql-cdc
CVE-2022-1295 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js