CVE-2018-10862
published 2018-07-27CVE-2018-10862: WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to…
PriorityP429medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
1.26%
66.4th percentile
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | virtualization | — | — |
| redhat | wildfly_core | <= 5.0.0 | — |
| redhat | wildfly_core | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Limitation of a Pathname to a Restricted Directory in WildFly
osv·2022-05-14
CVE-2018-10862 [MEDIUM] Improper Limitation of a Pathname to a Restricted Directory in WildFly
Improper Limitation of a Pathname to a Restricted Directory in WildFly
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
GHSA
Improper Limitation of a Pathname to a Restricted Directory in WildFly
ghsa·2022-05-14
CVE-2018-10862 [MEDIUM] CWE-22 Improper Limitation of a Pathname to a Restricted Directory in WildFly
Improper Limitation of a Pathname to a Restricted Directory in WildFly
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
Red Hat
wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)
vendor_redhat·2018-06-21·CVSS 5.5
CVE-2018-10862 [MEDIUM] CWE-22 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)
wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
It was found that the explode function of the deployment utility in jboss-cli and console that allows extraction of files from an archive does not perform necessary validation for directory traversal. This can lead to remote code execution.
Statement: This vulnerability can only be exploited by users with deployment permissions.
Package: wildfly (JBoss Developer Studio 11) - Not affected
Package: wildfly (Red Hat BPM Suite 6) - Not affected
Package:
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10862 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) [fedora-all]
bugzilla·2018-06-25·CVSS 5.5
CVE-2018-10862 [MEDIUM] CVE-2018-10862 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) [fedora-all]
CVE-2018-10862 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2018-10862 wildfly-common: wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) [epel-7]
bugzilla·2018-06-25·CVSS 5.5
CVE-2018-10862 [MEDIUM] CVE-2018-10862 wildfly-common: wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) [epel-7]
CVE-2018-10862 wildfly-common: wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg comm
Bugzilla
CVE-2018-10862 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)
bugzilla·2018-06-21·CVSS 5.5
CVE-2018-10862 [MEDIUM] CVE-2018-10862 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)
CVE-2018-10862 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)
WildFly does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files.
This is an instance of the 'Zip Slip' vulnerability.
Upstream Issue:
https://issues.jboss.org/browse/WFCORE-3938
External Reference:
https://snyk.io/research/zip-slip-vulnerability
Discussion:
Statement:
This vulnerability can only be exploited by users with deployment permissions.
---
Created wildfly-common tracking bugs for this issue:
Affects: epel-7 [bug 1594635]
Created wildfly-core tracking bugs for this issue:
Affects: fedora-all [bug 1594634]
---
This issue has been addressed in the following produc
https://access.redhat.com/errata/RHSA-2018:2276https://access.redhat.com/errata/RHSA-2018:2277https://access.redhat.com/errata/RHSA-2018:2279https://access.redhat.com/errata/RHSA-2018:2423https://access.redhat.com/errata/RHSA-2018:2424https://access.redhat.com/errata/RHSA-2018:2425https://access.redhat.com/errata/RHSA-2018:2428https://access.redhat.com/errata/RHSA-2018:2643https://access.redhat.com/errata/RHSA-2019:0877https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10862https://snyk.io/research/zip-slip-vulnerabilityhttps://access.redhat.com/errata/RHSA-2018:2276https://access.redhat.com/errata/RHSA-2018:2277https://access.redhat.com/errata/RHSA-2018:2279https://access.redhat.com/errata/RHSA-2018:2423https://access.redhat.com/errata/RHSA-2018:2424https://access.redhat.com/errata/RHSA-2018:2425https://access.redhat.com/errata/RHSA-2018:2428https://access.redhat.com/errata/RHSA-2018:2643https://access.redhat.com/errata/RHSA-2019:0877https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10862https://snyk.io/research/zip-slip-vulnerability
2018-07-27
Published