PT-2023-15892 · Jatos · Jatos

CVE-2022-4878

·

Publicado

2023-01-06

·

Atualizado

2024-05-17

CVSS v3.1

5.5

Média

VetorAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions JATOS versions prior to 3.7.5-alpha
Description A critical vulnerability has been found in JATOS, affecting the ZipUtil function of the ZIP Handler component. This issue leads to path traversal.
Recommendations For versions prior to 3.7.5-alpha, upgrade to version 3.7.5-alpha to address this issue. As a temporary workaround, consider disabling the ZipUtil function until the patch is applied. Restrict access to the ZIP Handler component to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-4878

Produtos afetados

Jatos