CVE-2018-1002202
Description
zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
In plain language
AI Worth attentionCVE-2018-1002202 is a “Zip-Slip” bug in Zip4j that can let a malicious zip write files anywhere on your computer when someone opens or processes the zip; if you use Zip4j and handle untrusted zips, you should update to 1.3.3.
In Zip4j (zip4j < 1.3.3), a directory traversal weakness (Zip-Slip, CWE-22) mishandles zip entry paths so crafted “../” paths can cause arbitrary file writes during extraction; it requires processing a malicious zip (user interaction) and has a network-reachable vector if your system accepts zips from users or the web.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:NConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-1002202 and every CVE in our database. Create a free account — no credit card required.
Create Free Account