CVE-2018-10862

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
redhatvirtualization
4.0
redhatjboss_enterprise_application_platform
7.1.0
redhatjboss_enterprise_application_platform
7.1.0
redhatwildfly_core
𝑥
≤ 5.0.0
redhatwildfly_core
6.0.0:alpha1
redhatwildfly_core
6.0.0:alpha2
𝑥
= Vulnerable software versions