Pivotal Spring-integration-zip是美国Pivotal Software公司的一款使用在Spring中的压缩/解压缩组件。 Pivotal Spring-integration-zip 1.0.1之前版本中存在任意文件写入漏洞。攻击者可借助特制的zip(还包括bzip2、tar、xz、war、cpio和7z)归档文件利用该漏洞写入任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Pivotal | Spring Integration Zip | 5.0.x prior to 5.0.6; 4.3.x prior to 4.3.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-1257 | Pivotal Spring Framework 输入验证错误漏洞 | |
| CVE-2018-1258 | Vmware Spring Framework和VMware Spring Security 授权问题漏洞 | |
| CVE-2018-1259 | Pivotal Spring Data Commons 安全漏洞 | |
| CVE-2018-1260 | Pivotal Spring Security Oauth 安全漏洞 | |
| CVE-2018-1278 | Pivotal Application Service Apps Manager 安全漏洞 | |
| CVE-2018-1280 | Pivotal Greenplum Command Center SQL注入漏洞 |
No comments yet