Description
A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to path traversal. Upgrading to version 0.5.2-pre2-alpha is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216747.
References (3)
Core 3
Core References
Third Party Advisory technical-description
vdb-entry
https://vuldb.com/?id.216747
Patch, Third Party Advisory mitigation
https://github.com/Calsign/APDE/commit/c6d64cbe465348c1bfd211122d89e3117afadecf
Release Notes, Third Party Advisory mitigation
https://github.com/Calsign/APDE/releases/tag/v0.5.2-pre2-alpha
Scores
CVSS v3
5.5
EPSS
0.0087
EPSS Percentile
54.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-22
Status
published
Products (2)
android_processing_development_environment_project/android_processing_development_environment
0.5.2 pre1_alpha
android_processing_development_environment_project/android_processing_development_environment
< 0.5.2
Published
Dec 25, 2022
Tracked Since
Feb 18, 2026