CVE-2023-39135

HIGH

Zip Swift 2.1.2 - Path Traversal via Crafted Zip Entry

Title source: llm
STIX 2.1

Description

An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry.

References (4)

Core 4
Core References
Exploit, Issue Tracking, Vendor Advisory
https://github.com/marmelroy/Zip/issues/245
Exploit, Third Party Advisory
https://ostorlab.co/vulndb/advisory/OVE-2023-1

Scores

CVSS v3 7.8
EPSS 0.0044
EPSS Percentile 35.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
marmelroy/zip 2.1.2
SwiftURL/github.com/marmelroy/Zip 0SwiftURL
Published Aug 30, 2023
Tracked Since Feb 18, 2026