-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.uima:uimaj-core | maven | < 3.3.1 | 3.3.1 |
The vulnerability description specifically identifies the FileUtil class in PEAR management as the vulnerable component. File extraction functions handling ZIP entries would be the primary location for path traversal vulnerabilities. The function name follows standard Java package conventions for UIMA (org.apache.uima.util). While the exact code changes aren't shown, the vulnerability pattern matches unsafe ZipEntry name handling in file extraction methods.
KEV Misses 88% of Exploited CVEs- Get the report