CVE-2022-32287
HIGHApache UIMA < 3.3.0 - Path Traversal via ZIP Entry in PEAR File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-32287. PoCs published by shoucheng3.
AI-analyzed exploit summary The repository appears to be a fork or snapshot of the Apache UIMA project with no explicit exploit code or technical analysis related to CVE-2022-32287. It contains standard project files (e.g., CI workflows, issue templates) but lacks any PoC, scanner, or writeup specific to the vulnerability.
Description
A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.
Exploits (1)
The repository appears to be a fork or snapshot of the Apache UIMA project with no explicit exploit code or technical analysis related to CVE-2022-32287. It contains standard project files (e.g., CI workflows, issue templates) but lacks any PoC, scanner, or writeup specific to the vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N