Deep Java Library
cpe:2.3:a:djl:deep_java_library:*:*:*:*:*:*:*
- >= 0.1.0, <= 0.31.0
A path traversal vulnerability has been identified in the Deep Java Library (DJL) version 0.1.0 prior to 0.31.0. This issue affects the ZipUtils.unzip and TarUtils.untar functions across all platforms, allowing an attacker to write files to arbitrary locations. Exploitation of this vulnerability could lead to unauthorized SSH access by injecting an SSH key into the authorized_keys file, or the upload of HTML files that could be used to exploit cross-site scripting vulnerabilities.
Exploitation of this vulnerability could allow an attacker to gain SSH access by injecting an SSH key into the authorized_keys file, or to upload HTML files that could be used to exploit cross-site scripting vulnerabilities.
Users of Deep Java Library are advised to upgrade to version 0.31.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.