CVE-2026-102332: Dozzle before 11.1.2 Path Traversal via Log ZIP Download
Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the extraction directory when users download and extract logs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dozzleto a version that resolves this vulnerability.Fixed in 11.1.2
Event History
Frequently Asked Questions
Who can exploit this issue in practice?
An attacker needs the ability to set or influence a container display name. Exploitation also requires a user to download logs from the affected endpoint and extract the resulting ZIP archive.
What is the impact on the person extracting the logs?
A malicious container display name can cause ZIP entries to contain path traversal sequences. When the archive is extracted, files may be written outside the intended extraction directory, potentially overwriting files where the extracting user has permission.
Which versions should be remediated?
Dozzle versions before 11.1.2 are affected. Upgrade to version 11.1.2 or later.