CVE-2018-8008

Description

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
15.35

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-1332,CVE-2018-1331,CVE-2018-8008 are fixed in Apache-storm-core 1.1.3Windows
Vulnerabilities CVE-2018-1332,CVE-2018-1331,CVE-2018-8008 are fixed in Apache-storm-core 1.2.2Windows
Vulnerabilities CVE-2018-8008 are fixed in Apache-storm-core 1.0.7Windows
Vulnerabilities CVE-2018-1332,CVE-2018-1331,CVE-2018-8008 are fixed in Apache-storm-core for Linux 1.1.3Linux
Vulnerabilities CVE-2018-1332,CVE-2018-1331,CVE-2018-8008 are fixed in Apache-storm-core for Linux 1.2.2Linux
Vulnerabilities CVE-2018-8008 are fixed in Apache-storm-core for Linux 1.0.7Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234