Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-1271 | gzip (CWE-1035) #889

Open
yeyisan opened this issue Apr 26, 2022 · 0 comments
Open

CVE-2022-1271 | gzip (CWE-1035) #889

yeyisan opened this issue Apr 26, 2022 · 0 comments
Labels
bug Something isn't working KONDUKTO

Comments

@yeyisan
Copy link
Collaborator

yeyisan commented Apr 26, 2022

A high severity vulnerability has been discovered in your project.

Project Name: Node

Scanner Name: trivy

Cwe ID: 1035

Cwe Name: Using Components with Known Vulnerabilities

Cwe Link: https://cwe.mitre.org/data/definitions/1035.html

CVE ID: CVE-2022-1271

Target: redis:latest (debian 11.3)

Packages:

  • gzip : 1.10-4 - Fixed Version: 1.10-4+deb11u1

References:

Tool Description: An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

Custom Description: hh

@yeyisan yeyisan added bug Something isn't working KONDUKTO labels Apr 26, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working KONDUKTO
Projects
None yet
Development

No branches or pull requests

1 participant