Security Advisory

CVE-2021-43099

4.9
MEDIUM

Vulnerability Description

An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction.java, which unzips the arbitrary upladed zip file without checking filenames. The vulnerability is exploited using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe).
Published Date March 28, 2022
Official Source NIST NVD Advisory