CRITICALMaven →
Arbitrary File Creation in AbstractUnArchiver
Arbitrary File Creation in AbstractUnArchiver
Affected packages
- org.codehaus.plexus:plexus-archiver— before 4.8.0
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/codehaus-plexus/plexus-archiver/security/advisories/GHSA-wh3p-fphp-9h2m
- https://nvd.nist.gov/vuln/detail/CVE-2023-37460
- https://github.com/codehaus-plexus/plexus-archiver/commit/54759839fbdf85caf8442076f001d5fd64e0dcb2
- https://github.com/codehaus-plexus/plexus-archiver
- https://github.com/codehaus-plexus/plexus-archiver/releases/tag/plexus-archiver-4.8.0
Structured record: https://osv.dev/vulnerability/GHSA-wh3p-fphp-9h2m
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta