CVE-2022-48285Path Traversal in Project Jszip

Severity
7.3HIGHNVD
EPSS
1.2%
top 21.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29
Latest updateOct 15

Description

loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages11 packages

debiandebian/node-jszip< node-jszip 3.10.0+dfsg-1 (bookworm)
NVDjszip_project/jszip< 3.8.0
npmjszip_project/jszip< 3.8.0

Patches

🔴Vulnerability Details

3
OSV
CVE-2022-48285: loadAsync in JSZip before 32023-01-29
OSV
JSZip contains Path Traversal via loadAsync2023-01-29
GHSA
JSZip contains Path Traversal via loadAsync2023-01-29

📋Vendor Advisories

5
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Installer (JSZip) — CVE-2022-482852023-10-15
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Admin (JSZip) — CVE-2022-482852023-07-15
Red Hat
jszip: directory traversal via a crafted ZIP archive2023-01-29
Microsoft
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.2023-01-10
Debian
CVE-2022-48285: node-jszip - loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP arc...2022
CVE-2022-48285 — Path Traversal in Jszip Project Jszip | cvebase