PT-2022-6761 · Jszip+1 · Jszip+1

·

CVE-2022-48285

·

Published

2022-03-30

·

Updated

2024-08-01

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JSZip versions prior to 3.8.0
Description The issue is related to the loadAsync function in JSZip, which allows directory traversal via a crafted ZIP archive. This can be exploited by a remote attacker to write arbitrary files and execute arbitrary commands using a specially crafted malicious ZIP archive.
Recommendations For versions prior to 3.8.0, update to version 3.8.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the loadAsync function until a patch is available. Avoid using the loadAsync function with untrusted ZIP archives until the issue is resolved.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-38236
AZL-57076
BDU:2023-04192
CVE-2022-48285
GHSA-36FH-84J7-CV5H

Affected Products

Debian
Jszip