Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Arbitrary File Write via Archive Extraction (Zip Slip)
Vulnerability Description
The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
zip-local 路径遍历漏洞
Vulnerability Description
Zip-Local是Mostafa Samir个人开发者的一个非常简单的压缩 /Uzipping 本地文件和节点中的目录 .Js。 zip-local 0.3.5之前版本存在安全漏洞,该漏洞可进行任意文件写的攻击。
CVSS Information
N/A
Vulnerability Type
N/A