CVE-2018-1263
Last modified
CVE-2018-1263 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. EPSS estimates a 1.45% chance of exploitation in the next 30 days.
Description
Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Integration Zip | < 1.0.2 |
References
- http://www.securityfocus.com/bid/104179Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2018-1263Vendor Advisory
- http://www.securityfocus.com/bid/104179Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2018-1263Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1263?
How severe is CVE-2018-1263?
How do I fix CVE-2018-1263?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12623An issue was discovered in Eventum 3.5.0. htdocs/switch.php …
- CVE-2018-12624An issue was discovered in Eventum 3.5.0. /htdocs/post_note.…
- CVE-2018-12625An issue was discovered in Eventum 3.5.0. /htdocs/validate.p…
- CVE-2018-12626An issue was discovered in Eventum 3.5.0. /htdocs/popup.php …
- CVE-2018-12627An issue was discovered in Eventum 3.5.0. /htdocs/list.php h…
- CVE-2018-12628An issue was discovered in Eventum 3.5.0. CSRF in htdocs/man…
- CVE-2018-12630NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via th…
- CVE-2018-12631Redatam7 (formerly Redatam WebServer) allows remote attacker…
- CVE-2018-12632Redatam7 (formerly Redatam WebServer) allows remote attacker…
- CVE-2018-12633An issue was discovered in the Linux kernel through 4.17.2. …
- CVE-2018-12634CirCarLife Scada before 4.3 allows remote attackers to obtai…9.8
- CVE-2018-12635CirCarLife Scada v4.2.4 allows unauthorized upgrades via req…
Are you affected by CVE-2018-1263?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
