GHSA-cmwm-45mj-mpg3
CRITICALCVE-2022-4493A vulnerability classified as critical was found in scifio. Affected by this vulnerability is the function downloadAndUnpackResource of the file src/test/java/io/scif/util/DefaultSampleFilesService.java of the component ZIP File Handler. The manipulation leads to path traversal. The attack can be launched remotely. The patch is at commit fcb0dbca0ec72b22fe0c9ddc8abc9cb188a0ff31. It is recommended
- Affected
- < 0.43.3
- Fixed in
- 0.43.3
- Weakness
- CWE-22
- Published
- 2022-12-14
- Source
- github