Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

7He6Uzzer

#27194of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2022-9401
9.8
2022-01-28
Zip-Local · Zip-Local · CVE-2021-23484
**Name of the Vulnerable Software and Affected Versions** zip-local versions prior to 0.3.5 **Description** The issue allows for Arbitrary File Write via Archive Extraction, also known as Zip Slip, which can lead to the extraction of a crafted file outside the intended extraction directory. This can potentially cause security problems. **Recommendations** For versions prior to 0.3.5, update to version 0.3.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of archive extraction functions until a patch is applied.