漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Fedora Repository archive extraction path traversal
Vulnerability Description
Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be executed by an unauthenticated GET request. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
相对路径遍历
Vulnerability Title
Fedora 安全漏洞
Vulnerability Description
Fedora是Fedora社区的一套Linux操作系统。 Fedora 3.8.1版本存在安全漏洞,该漏洞源于存在路径遍历漏洞,允许攻击者将任意JSP文件放置于可通过未认证GET请求执行的位置。
CVSS Information
N/A
Vulnerability Type
N/A