Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Fedora Repository archive extraction path traversal
Vulnerability Description
Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be executed by an unauthenticated GET request. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
相对路径遍历
Vulnerability Title
Fedora 安全漏洞
Vulnerability Description
Fedora是Fedora社区的一套Linux操作系统。 Fedora 3.8.1版本存在安全漏洞,该漏洞源于存在路径遍历漏洞,允许攻击者将任意JSP文件放置于可通过未认证GET请求执行的位置。
CVSS Information
N/A
Vulnerability Type
N/A