CVE-2020-36628

MEDIUM

Calsign APDE <0.5.2-pre2-alpha - Path Traversal

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to path traversal. Upgrading to version 0.5.2-pre2-alpha is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216747.

References (3)

Core 3
Core References
Third Party Advisory technical-description vdb-entry
https://vuldb.com/?id.216747
Release Notes, Third Party Advisory mitigation
https://github.com/Calsign/APDE/releases/tag/v0.5.2-pre2-alpha

Scores

CVSS v3 5.5
EPSS 0.0087
EPSS Percentile 54.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-22
Status published
Products (2)
android_processing_development_environment_project/android_processing_development_environment 0.5.2 pre1_alpha
android_processing_development_environment_project/android_processing_development_environment < 0.5.2
Published Dec 25, 2022
Tracked Since Feb 18, 2026