Deep Java Library Path Traversal Vulnerability in Zip and Tar Utilities

Vulnerability

A path traversal vulnerability has been identified in the Deep Java Library (DJL) version 0.1.0 prior to 0.31.0. This issue affects the ZipUtils.unzip and TarUtils.untar functions across all platforms, allowing an attacker to write files to arbitrary locations. Exploitation of this vulnerability could lead to unauthorized SSH access by injecting an SSH key into the authorized_keys file, or the upload of HTML files that could be used to exploit cross-site scripting vulnerabilities.

Impact

Exploitation of this vulnerability could allow an attacker to gain SSH access by injecting an SSH key into the authorized_keys file, or to upload HTML files that could be used to exploit cross-site scripting vulnerabilities.

Remediation

Users of Deep Java Library are advised to upgrade to version 0.31.1 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.2
impact
2.5
exploitability
4.7
remediation
7.9
relevance
0.0
threat
0.5
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.