CVE-2024-24569

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
01/02/2024
Last modified:
09/02/2024

Description

The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurrentDirectory` is vulnerable to a partial-path traversal bypass. To be vulnerable to the bypass, the application must use toolkit version

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pixee:java_code_security_toolkit:*:*:*:*:*:*:*:* 1.1.2 (excluding)