VDB
Sign up
HIGH

GHSA-5458-7hh9-v7p4

pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names

Quick fix

GHSA-5458-7hh9-v7p4 — org.pf4j:pf4j: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.14.1</version> for org.pf4j:pf4j

Details

pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.pf4j:pf4j
Introduced in: 0Fixed in: 3.14.1
Fix# pom.xml: bump <version>3.14.1</version> for org.pf4j:pf4j

References