HIGH7.3
GHSA-36fh-84j7-cv5h
JSZip contains Path Traversal via loadAsync
Quick fix
GHSA-36fh-84j7-cv5h — jszip: upgrade to the fixed version with the command below.
npm install jszip@3.8.0Details
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-48285[ADVISORY]
- https://github.com/Stuk/jszip/commit/2edab366119c9ee948357c02f1206c28566cdf15[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/244499[WEB]
- https://github.com/Stuk/jszip[PACKAGE]
- https://github.com/Stuk/jszip/compare/v3.7.1...v3.8.0[WEB]
- https://security.netapp.com/advisory/ntap-20240621-0005[WEB]
- https://www.mend.io/vulnerability-database/WS-2023-0004[WEB]