ZeroHour

CVE-2018-10862

CVSS 3.0
5.5 medium
EPSS
1%p68
Published
()
Modified
Description

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

Vendors
redhat
Products
virtualization, jboss enterprise application platform, wildfly core
Weakness
CWE-22
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.