A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.
References
Link | Resource |
---|---|
https://github.com/kuba--/zip/issues/123 | Exploit Issue Tracking Third Party Advisory |
https://github.com/kuba--/zip/issues/123 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-08-10 17:15
Updated : 2024-11-21 05:13
NVD link : CVE-2020-23172
Mitre link : CVE-2020-23172
CVE.ORG link : CVE-2020-23172
JSON object : View
Products Affected
kuba_project
- kuba
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')