Improper Input Validation Affecting archive package, versions <3.3.8
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.06% (26th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PUB-ARCHIVE-5880302
- published 3 Sep 2023
- disclosed 31 Aug 2023
- credit Unknown
Introduced: 31 Aug 2023
CVE-2023-39137 Open this link in a new tabHow to fix?
Upgrade archive
to version 3.3.8 or higher.
Overview
Affected versions of this package are vulnerable to Improper Input Validation. An attacker can spoof zip filenames, leading to inconsistent filename parsing by crafting a malicious zip file with different file names in Local File Header
and Central Directory Entry
, consequently having a file with different filenames before and after extraction.
References
CVSS Scores
version 3.1