Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be executed by an unauthenticated GET request. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 19 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Fedorarepository
         Fedorarepository fcrepo  | 
|
| CPEs | cpe:2.3:a:fedorarepository:fcrepo:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Fedorarepository
         Fedorarepository fcrepo  | 
Thu, 06 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 23 Jan 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be executed by an unauthenticated GET request. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23). | |
| Title | Fedora Repository archive extraction path traversal | |
| Weaknesses | CWE-23 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
 
  | 
Status: PUBLISHED
Assigner: cisa-cg
Published: 2025-01-23T20:22:30.958Z
Updated: 2025-02-06T21:27:16.765Z
Reserved: 2025-01-09T16:12:23.684Z
Link: CVE-2025-23011
Updated: 2025-01-23T20:56:27.380Z
Status : Analyzed
Published: 2025-01-23T21:15:15.010
Modified: 2025-09-19T18:30:34.980
Link: CVE-2025-23011
No data.