CVE-2023-39138
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Aug 30, 2023
Updated: Sep 5, 2023
CWE ID 22
Summary
CVE-2023-39138 is a newly discovered vulnerability affecting ZIPFoundation version 0.9.16. This issue permits attackers to conduct path traversal attacks by extracting specially crafted ZIP files, potentially leading to unintended directory access or data leakage. Malicious actors can exploit this weakness to access sensitive information or execute arbitrary code beyond intended boundaries. Users are advised to update their ZIPFoundation packages to a secure version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share