VDB
CISA-2022-48285
CISA-2022-48285
PUBLISHED
CVSS 7.3 HIGH
Reported by mitre · Published January 29, 2023
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
Risk Scores
CVSS 3.1
7.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| jszip_project | jszip | 0, 0 |
| n/a | n/a | n/a, n/a |
Timeline
- Jan 29, 2023 CVE Published
- Aug 3, 2024 CVE Updated