CVE-2018-10862

EUVD-2022-5534
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Affected Products (NVD)
VendorProductVersion
redhatvirtualization
4.0
redhatjboss_enterprise_application_platform
7.1.0
redhatjboss_enterprise_application_platform
7.1.0
redhatwildfly_core
𝑥
≤ 5.0.0
redhatwildfly_core
6.0.0:alpha1
redhatwildfly_core
6.0.0:alpha2
𝑥
= Vulnerable software versions