Loading HuntDB...

GHSA-m9jm-rhrm-gcxj

GitHub Security Advisory

Path traversal in org.springframework.integration:spring-integration-zip

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

Affected Packages

Maven org.springframework.integration:spring-integration-zip
Affected versions: 0 (fixed in 1.0.1)

Related CVEs

Key Information

GHSA ID
GHSA-m9jm-rhrm-gcxj
Published
October 18, 2018 6:05 PM
Last Modified
April 12, 2024 9:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.springframework.integration:spring-integration-zip
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 5, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.