{"id":"GHSA-xhg6-9j5j-w4vf","summary":"DotNetZip Directory Traversal vulnerability","details":"Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component.","aliases":["CVE-2024-48510"],"modified":"2024-11-25T20:23:02.866584Z","published":"2024-11-13T15:31:37Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-11-13T18:38:01Z","nvd_published_at":"2024-11-13T15:15:07Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-48510"},{"type":"WEB","url":"https://github.com/mihula/ProDotNetZip/pull/21"},{"type":"WEB","url":"https://github.com/mihula/ProDotNetZip/commit/18486ad6d13742a07a6755ef6edf60d7458f1854"},{"type":"WEB","url":"https://gist.github.com/thomas-chauchefoin-bentley-systems/855218959116f870f08857cce2aec731"},{"type":"PACKAGE","url":"https://github.com/haf/DotNetZip.Semverd"},{"type":"WEB","url":"https://github.com/haf/DotNetZip.Semverd/blob/e487179b33a9a0f2631eed5fb04d2c952ea5377a/src/Zip.Shared/ZipEntry.Extract.cs#L1365-L1410"},{"type":"WEB","url":"https://www.nuget.org/packages/DotNetZip"}],"affected":[{"package":{"name":"DotNetZip","ecosystem":"NuGet","purl":"pkg:nuget/DotNetZip"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.10.1"},{"last_affected":"1.16.0"}]}],"versions":["1.10.1","1.11.0","1.12.0","1.13.0","1.13.1","1.13.2","1.13.3","1.13.4","1.13.5","1.13.6","1.13.7","1.13.8","1.14.0","1.15.0","1.16.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-xhg6-9j5j-w4vf/GHSA-xhg6-9j5j-w4vf.json"}},{"package":{"name":"ProDotNetZip","ecosystem":"NuGet","purl":"pkg:nuget/ProDotNetZip"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.19.0"}]}],"versions":["1.16.0","1.17.0","1.18.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-xhg6-9j5j-w4vf/GHSA-xhg6-9j5j-w4vf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}