Back

HIGH

wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)

Published Jul 27, 2018

Description

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

Affected products

Remediation

Red Hat statement

This vulnerability can only be exploited by users with deployment permissions.

Metrics

Weaknesses (1)

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 27, 2018
Updated Aug 5, 2024
Reserved May 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 21, 2018
GHSA-W8R2-5J8X-X8J6