The Plexus project provides a full software stack for creating and executing software projects.
Language
JAVA
Vulnerability
Arbitrary File Write
Vulnerability description
Plexus Archiver Component is vulnerable to zip-slip vulnerability. The vulnerability exists when the attacker inputs a malicious zip archive with filenames including file traversal characters such as dot dot (..), leading to concatenation of file path locating outside of the destination folder.
Veracode Software Composition Analysis
..
), leading to concatenation of file path locating outside of the destination folder.Links: