Fedora Repository 3.8.1 allows path traversal when...
High severity
Unreviewed
Published
Jan 23, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jan 23, 2025
Published to the GitHub Advisory Database
Jan 23, 2025
Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be executed by an unauthenticated GET request. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).
References