CVE-2018-10862: Path Traversal
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
Other sources
WildFly does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files.
This is an instance of the 'Zip Slip' vulnerability.
Upstream Issue:
https://issues.jboss.org/browse/WFCORE-3938
External Reference:
https://snyk.io/research/zip-slip-vulnerability
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10862?
CVE-2018-10862 is a vulnerability in WildFly Core that allows for the extraction of crafted .war archives to overwrite arbitrary files.
What is the severity of CVE-2018-10862?
The severity of CVE-2018-10862 is high, with a severity value of 5.5.
How does CVE-2018-10862 impact WildFly Core?
CVE-2018-10862 impacts WildFly Core before version 6.0.0.Alpha3 and allows for the extraction of crafted .war archives to overwrite arbitrary files.
How can I fix CVE-2018-10862?
To fix CVE-2018-10862, upgrade WildFly Core to version 6.0.0.Alpha3 or higher.
Where can I find more information about CVE-2018-10862?
You can find more information about CVE-2018-10862 at the following references: [1] [2] [3]