Path Traversal in com.alibaba.oneagent:one-java-agent-plugin
Moderate severity
GitHub Reviewed
Published
May 3, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
< 0.0.2
Patched versions
0.0.2
Description
Published by the National Vulnerability Database
May 1, 2022
Published to the GitHub Advisory Database
May 3, 2022
Reviewed
May 20, 2022
Last updated
Feb 1, 2023
All versions of package
com.alibaba.oneagent:one-java-agent-plugin
are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g.../../evil.exe
). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.References