Advisories for Maven/Org.codehaus.plexus/Plexus-Archiver package

2023

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified Archiver/UnArchiver API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting an archive with an entry that already exists in the destination directory as a symbolic link whose target does not exist - the resolveFile() …

2022