Plexus-archiver security update (CESA-2018:1836) plexus-archiver-2.4.2-5.el7_5.noarch.rpm
Risk Information
Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
No records foundCVE Information
Patch Details
No records found
References
https://access.redhat.com/errata/RHSA-2018:1836
https://access.redhat.com/errata/RHSA-2018:1837
https://github.com/codehaus-plexus/plexus-archiver/commit/f8f4233508193b70df33759ae9dc6154d69c2ea8
https://github.com/codehaus-plexus/plexus-archiver/pull/87
https://github.com/snyk/zip-slip-vulnerability
https://snyk.io/research/zip-slip-vulnerability
https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31680
https://www.debian.org/security/2018/dsa-4227