Directory Traversal Affecting xmvn-mojo package, versions <4.2.0-150200.3.14.1


Severity

Recommended
0.0
low
0
10

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.05% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Directory Traversal vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-SLES152-XMVNMOJO-6083262
  • published23 Nov 2023
  • disclosed22 Nov 2023

Introduced: 22 Nov 2023

CVE-2023-46122  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

Upgrade SLES:15.2 xmvn-mojo to version 4.2.0-150200.3.14.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream xmvn-mojo package and not the xmvn-mojo package as distributed by SLES. See How to fix? for SLES:15.2 relevant fixed versions and status.

sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, IO.unzip allows writing of arbitrary file. This would have potential to overwrite /root/.ssh/authorized_keys. Within sbt's main code, IO.unzip is used in pullRemoteCache task and Resolvers.remote; however many projects use IO.unzip(...) directly to implement custom tasks. This vulnerability has been patched in version 1.9.7.

CVSS Scores

version 3.1