bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Bestzip_Project Bestzip
cpe:2.3:a:bestzip_project:bestzip:*:*:*:*:*:*:*:*
|
2.2.6
|
2.2.7
|
|
Bestzip_Project Bestzip
cpe:2.3:a:bestzip_project:bestzip:*:*:*:*:*:*:*:*
|
3.0.2
|
3.0.3
|