| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:zeroturnaround:zt-zip:*:*:*:*:*:*:*:* versions up to (excluding) 1.13 |
| Added |
CVSS V2 |
|
(AV:N/AC:M/Au:N/C:N/I:P/A:N) |
| Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism |
| Added |
CVSS V3 |
|
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
| Added |
CWE |
|
CWE-22 |
| Changed |
Reference Type |
https://github.com/snyk/zip-slip-vulnerability No Types Assigned |
https://github.com/snyk/zip-slip-vulnerability Exploit, Third Party Advisory |
| Changed |
Reference Type |
https://github.com/zeroturnaround/zt-zip/blob/zt-zip-1.13/Changelog.txt No Types Assigned |
https://github.com/zeroturnaround/zt-zip/blob/zt-zip-1.13/Changelog.txt Issue Tracking, Third Party Advisory |
| Changed |
Reference Type |
https://github.com/zeroturnaround/zt-zip/commit/759b72f33bc8f4d69f84f09fcb7f010ad45d6fff No Types Assigned |
https://github.com/zeroturnaround/zt-zip/commit/759b72f33bc8f4d69f84f09fcb7f010ad45d6fff Issue Tracking, Patch, Third Party Advisory |
| Changed |
Reference Type |
https://snyk.io/research/zip-slip-vulnerability No Types Assigned |
https://snyk.io/research/zip-slip-vulnerability Exploit, Issue Tracking, Patch, Third Party Advisory |
| Changed |
Reference Type |
https://snyk.io/vuln/SNYK-JAVA-ORGZEROTURNAROUND-31681 No Types Assigned |
https://snyk.io/vuln/SNYK-JAVA-ORGZEROTURNAROUND-31681 Exploit, Issue Tracking, Patch, Third Party Advisory |