Vulnerability

CVE-2022-48285
CVSS Score 8.2 high

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:H

CWE

CWE-29

[CVE-2022-48285] CWE-29: Path Traversal: '..filename'

Description

jszip - Arbitrary File Write via Archive Extraction (Zip Slip) The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '..filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.

See jszip package information