CVE-2022-35410
published 2022-07-08CVE-2022-35410: mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.12%
80.0th percentile
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 0xacab | mat2 | < 0.13.0 | 0.13.0 |
| 0xacab | mat2 | >= 0 < 0.12.1-2+deb11u1 | 0.12.1-2+deb11u1 |
| 0xacab | mat2 | >= 0 < 0.13.0-1 | 0.13.0-1 |
| 0xacab | mat2 | >= 0 < 0.13.0-1 | 0.13.0-1 |
| 0xacab | mat2 | >= 0 < 0.13.0-1 | 0.13.0-1 |
| 0xacab | mat2 | >= 0 < 0.13.0 | 0.13.0 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mat2 | < mat2 0.13.0-1 (bookworm) | mat2 0.13.0-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-35410: mat2 - mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory tra...
vendor_debian·2022·CVSS 7.5
CVE-2022-35410 [HIGH] CVE-2022-35410: mat2 - mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory tra...
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
Scope: local
bookworm: resolved (fixed in 0.13.0-1)
bullseye: resolved (fixed in 0.12.1-2+deb11u1)
forky: resolved (fixed in 0.13.0-1)
sid: resolved (fixed in 0.13.0-1)
trixie: resolved (fixed in 0.13.0-1)
OSV
mat2 before 0.13.0 allows directory traversal during the ZIP archive cleaning process.
osv·2022-07-12
CVE-2022-35410 [HIGH] mat2 before 0.13.0 allows directory traversal during the ZIP archive cleaning process.
mat2 before 0.13.0 allows directory traversal during the ZIP archive cleaning process.
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows `../` directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
GHSA
mat2 before 0.13.0 allows directory traversal during the ZIP archive cleaning process.
ghsa·2022-07-12
CVE-2022-35410 [HIGH] CWE-22 mat2 before 0.13.0 allows directory traversal during the ZIP archive cleaning process.
mat2 before 0.13.0 allows directory traversal during the ZIP archive cleaning process.
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows `../` directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
OSV
CVE-2022-35410: mat2 (aka metadata anonymisation toolkit) before 0
osv·2022-07-08·CVSS 7.5
CVE-2022-35410 [HIGH] CVE-2022-35410: mat2 (aka metadata anonymisation toolkit) before 0
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385https://0xacab.org/jvoisin/mat2/-/issues/174https://dustri.org/b/mat2-0130.htmlhttps://www.debian.org/security/2022/dsa-5185https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385https://0xacab.org/jvoisin/mat2/-/issues/174https://dustri.org/b/mat2-0130.htmlhttps://www.debian.org/security/2022/dsa-5185
2022-07-08
Published