PT-2026-28084 · Pf4J · Pf4J

CVE-2025-70952

·

Publicado

2026-03-25

·

Atualizado

2026-03-25

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pf4j versions prior to 20c2f80
Description The software contains a path traversal issue in the extract() function within the Unzip.java file. Improper handling of zip entry names can lead to directory traversal or Zip Slip attacks because of insufficient path normalization and validation.
Recommendations Update to version 20c2f80 or later.

Exploit

Correção

Relative Path Traversal

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-70952
GHSA-5458-7HH9-V7P4

Produtos afetados

Pf4J