Vulnerability Description
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Owasp | Dependency-Check | < 3.2.0 |
Related Weaknesses (CWE)
References
- https://github.com/jeremylong/DependencyCheck/blob/master/RELEASE_NOTES.md#versiRelease Notes
- https://github.com/snyk/zip-slip-vulnerabilityExploitThird Party Advisory
- https://github.com/jeremylong/DependencyCheck/blob/master/RELEASE_NOTES.md#versiRelease Notes
- https://github.com/snyk/zip-slip-vulnerabilityExploitThird Party Advisory
FAQ
What is CVE-2018-12036?
CVE-2018-12036 is a vulnerability with a CVSS score of 7.8 (HIGH). OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.
How severe is CVE-2018-12036?
CVE-2018-12036 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12036?
Check the references section above for vendor advisories and patch information. Affected products include: Owasp Dependency-Check.