Codehaus-Plexus Plexus-Archiver vulnerabilities
2 known vulnerabilities affecting codehaus-plexus/plexus-archiver.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-37460CRITICALCVSS 9.8fixed in 4.8.02023-07-25
CVE-2023-37460 [CRITICAL] CWE-22 CVE-2023-37460: Plexis Archiver is a collection of Plexus components to create archives or extract archives to a dir
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting an archive with an entry that a
nvd
CVE-2018-1002200MEDIUMCVSS 5.5fixed in 3.6.02018-07-25
CVE-2018-1002200 [MEDIUM] CWE-22 CVE-2018-1002200: plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to ar
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
nvdosv