CVE-2022-25842
Path Traversal in com.alibaba.oneagent:one-java-agent-plugin
6.9
MEDIUM
CVSS 3.1
EPSS 2.7%
Description
All versions of package `com.alibaba.oneagent:one-java-agent-plugin` are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. `../../evil.exe`). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.
How to fix CVE-2022-25842
To remediate CVE-2022-25842, upgrade the affected package to a fixed version below.
- —upgrade to 0.0.2 or later
Is CVE-2022-25842 being exploited?
Low — EPSS is 2.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.0.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:L |