de.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl@1.9.2 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the de.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Directory Traversal

de.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl is a DKPro Core module for loading publicly available datasets.

Affected versions of this package are vulnerable to Directory Traversal via core/api/datasets/internal/actions/Explode.java in the Dataset API in DKPro Core resulting in the overwrite of local files with the contents of an archive.

How to fix Directory Traversal?

A fix was pushed into the master branch but not yet published.

[0,)