{"id":"GHSA-jj8r-jw42-mw4w","summary":"Widoco Path Traversal vulnerability","details":"A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function `unZipIt` of the file `src/main/java/widoco/WidocoUtils.java`. The manipulation leads to path traversal. It is possible to launch the attack on the local host. The name of the patch is f2279b76827f32190adfa9bd5229b7d5a147fa92. It is recommended to apply a patch to fix this issue. VDB-216914 is the identifier assigned to this vulnerability.","aliases":["CVE-2022-4772"],"modified":"2023-11-01T05:00:31.277005Z","published":"2022-12-28T00:30:22Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-01-09T20:06:17Z","nvd_published_at":"2022-12-27T23:15:00Z","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4772"},{"type":"WEB","url":"https://github.com/dgarijo/Widoco/pull/551"},{"type":"WEB","url":"https://github.com/dgarijo/Widoco/commit/f2279b76827f32190adfa9bd5229b7d5a147fa92"},{"type":"PACKAGE","url":"https://github.com/dgarijo/Widoco"},{"type":"WEB","url":"https://vuldb.com/?ctiid.216914"},{"type":"WEB","url":"https://vuldb.com/?id.216914"}],"affected":[{"package":{"name":"com.github.dgarijo:Widoco","ecosystem":"Maven","purl":"pkg:maven/com.github.dgarijo/Widoco"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.4.17"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-jj8r-jw42-mw4w/GHSA-jj8r-jw42-mw4w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}