Vulnerability Description
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codehaus-Plexus | Plexus-Utils | < 3.6.1 |
Related Weaknesses (CWE)
References
- https://gist.github.com/weaver4VD/3216dac645220f8c9b488362f61241ecThird Party Advisory
- https://github.com/codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d295Patch
- https://github.com/codehaus-plexus/plexus-utils/issues/294Issue Tracking
- https://github.com/codehaus-plexus/plexus-utils/pull/295Issue TrackingPatch
- https://github.com/codehaus-plexus/plexus-utils/pull/296Issue TrackingPatch
FAQ
What is CVE-2025-67030?
CVE-2025-67030 is a vulnerability with a CVSS score of 8.8 (HIGH). Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbit...
How severe is CVE-2025-67030?
CVE-2025-67030 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67030?
Check the references section above for vendor advisories and patch information. Affected products include: Codehaus-Plexus Plexus-Utils.