CVE-2018-20227: Path Traversal
Published Dec 19, 2018
·Updated
RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.
Other sources
RDF4J prior to 2.5.0 allows Directory Traversal via ../ in an entry in a ZIP archive.
— GitHub
Affected Software
3 affected componentsFixes available
Eclipse RDF4j=2.4.2
Eclipse RDF4j<2.5.0
maven/org.eclipse.rdf4j:rdf4j<2.5.0
2.5.0
Remediation
Event History
Dec 19, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
May 14, 2022
Advisory Published
via GitHub·01:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-20227?
CVE-2018-20227 has a medium severity rating due to its potential for directory traversal vulnerabilities.
2
How do I fix CVE-2018-20227?
To fix CVE-2018-20227, upgrade to Eclipse RDF4J version 2.5.0 or later.
3
Who is affected by CVE-2018-20227?
CVE-2018-20227 affects users of Eclipse RDF4J versions prior to 2.5.0.
4
What type of vulnerability is CVE-2018-20227?
CVE-2018-20227 is a directory traversal vulnerability that can be exploited through ZIP archive entries.
5
Is CVE-2018-20227 exploitable in production environments?
Yes, CVE-2018-20227 can be exploited in production environments if vulnerable versions of RDF4J are in use.