-
-
Save weaver4VD/3216dac645220f8c9b488362f61241ec to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| [CVE ID] | |
| CVE-2025-67030 | |
| [Product] | |
| plexus | |
| [Version] | |
| before 6d780b3378829318ba5c2d29547e0012d5b29642 | |
| [Vulnerability Type] | |
| CWE-22 Directory Traversal | |
| [Description] | |
| Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code | |
| [Reference] | |
| https://github.com/codehaus-plexus/plexus-utils/pull/295 | |
| https://github.com/codehaus-plexus/plexus-utils/issues/294 | |
| https://github.com/codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d29547e0012d5b29642 | |
| https://github.com/codehaus-plexus/plexus-utils/pull/296 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
For 3.6.x fixed in
codehaus-plexus/plexus-utils@36ea352
Version 3.6.1 released - https://github.com/codehaus-plexus/plexus-utils/releases/tag/plexus-utils-3.6.1