Show plain JSON{"affected_release": [{"advisory": "RHSA-2020:2321", "cpe": "cpe:/a:redhat:jboss_data_grid:7.3", "package": "wildfly", "product_name": "Red Hat Data Grid 7.3.6", "release_date": "2020-05-26T00:00:00Z"}, {"advisory": "RHSA-2018:2277", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1", "product_name": "Red Hat JBoss EAP 7.1", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2425", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1", "package": "wildfly", "product_name": "Red Hat JBoss EAP 7.1", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2276", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-apache-cxf-0:3.1.16-1.redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2276", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-wildfly-0:7.1.3-4.GA_redhat_3.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2276", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-wss4j-0:2.1.12-1.redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2276", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-xml-security-0:2.0.10-1.redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2423", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7::el6", "package": "eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2276", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-apache-cxf-0:3.1.16-1.redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2276", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-wildfly-0:7.1.3-4.GA_redhat_3.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2276", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-wss4j-0:2.1.12-1.redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2276", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-xml-security-0:2.0.10-1.redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-activemq-artemis-0:1.5.5.013-1.redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-bouncycastle-0:1.56.0-5.redhat_3.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-guava-libraries-0:25.0.0-1.redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-hibernate-0:5.1.15-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-ironjacamar-0:1.4.10-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-jberet-0:1.2.6-2.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-jboss-ejb-client-0:4.0.11-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-jboss-remoting-0:5.0.8-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-jboss-server-migration-0:1.0.6-4.Final_redhat_4.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-mod_cluster-0:1.3.10-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-narayana-0:5.5.32-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-picketlink-bindings-0:2.5.5-13.SP12_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-picketlink-federation-0:2.5.5-13.SP12_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-resteasy-0:3.0.26-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-undertow-0:1.4.18-7.SP8_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-wildfly-0:7.1.4-1.GA_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-wildfly-javadocs-0:7.1.4-2.GA_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-wildfly-naming-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-wildfly-openssl-linux-0:1.0.6-14.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-wildfly-transaction-client-0:1.0.4-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2424", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7", "package": "eap7-wildfly-web-console-eap-0:2.9.18-1.Final_redhat_1.1.ep7.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2020:2562", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform_cd:13", "package": "wildfly", "product_name": "Red Hat JBoss Enterprise Application Platform Continuous Delivery", "release_date": "2020-06-15T00:00:00Z"}, {"advisory": "RHSA-2018:2279", "cpe": "cpe:/a:redhat:jboss_single_sign_on:7.2", "package": "wildfly", "product_name": "Red Hat Single Sign-On 7.2", "release_date": "2018-07-26T00:00:00Z"}, {"advisory": "RHSA-2018:2428", "cpe": "cpe:/a:redhat:jboss_single_sign_on:7.2", "package": "wildfly", "product_name": "Red Hat Single Sign-On 7.2.4 zip", "release_date": "2018-08-15T00:00:00Z"}, {"advisory": "RHSA-2018:2643", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "impact": "low", "package": "rhvm-appliance-0:4.2-20180828.0.el7", "product_name": "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7", "release_date": "2018-09-04T00:00:00Z"}, {"advisory": "RHSA-2019:0877", "cpe": "cpe:/a:redhat:openshift_application_runtimes:1.0", "product_name": "Text-Only RHOAR", "release_date": "2019-04-24T00:00:00Z"}], "bugzilla": {"description": "wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)", "id": "1593527", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1593527"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.6", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L", "status": "verified"}, "cwe": "CWE-22", "details": ["WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.", "It was found that the explode function of the deployment utility in jboss-cli and console that allows extraction of files from an archive does not perform necessary validation for directory traversal. This can lead to remote code execution."], "name": "CVE-2018-10862", "package_state": [{"cpe": "cpe:/a:redhat:jboss_dev_studio:11.", "fix_state": "Not affected", "package_name": "wildfly", "product_name": "JBoss Developer Studio 11"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform", "fix_state": "Not affected", "package_name": "wildfly", "product_name": "Red Hat BPM Suite 6"}, {"cpe": "cpe:/a:redhat:jboss_fuse:7", "fix_state": "Not affected", "package_name": "wildfly", "product_name": "Red Hat Fuse 7"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_brms_platform:6", "fix_state": "Not affected", "package_name": "wildfly", "product_name": "Red Hat JBoss BRMS 6"}, {"cpe": "cpe:/a:redhat:jboss_data_grid:6", "fix_state": "Not affected", "package_name": "wildfly", "product_name": "Red Hat JBoss Data Grid 6"}, {"cpe": "cpe:/a:redhat:jboss_data_virtualization:6", "fix_state": "Out of support scope", "package_name": "wildfly", "product_name": "Red Hat JBoss Data Virtualization 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6", "fix_state": "Not affected", "package_name": "wildfly", "product_name": "Red Hat JBoss Enterprise Application Platform 6"}, {"cpe": "cpe:/a:redhat:jboss_fuse:6", "fix_state": "Not affected", "package_name": "wildfly", "product_name": "Red Hat JBoss Fuse 6"}, {"cpe": "cpe:/a:redhat:jboss_operations_network:3", "fix_state": "Not affected", "package_name": "wildfly", "product_name": "Red Hat JBoss Operations Network 3"}, {"cpe": "cpe:/a:redhat:openshift_application_runtimes:1.0", "fix_state": "Affected", "package_name": "wildfly", "product_name": "Red Hat OpenShift Application Runtimes"}], "public_date": "2018-06-21T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2018-10862\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-10862\nhttps://snyk.io/research/zip-slip-vulnerability"], "statement": "This vulnerability can only be exploited by users with deployment permissions.", "threat_severity": "Important"}