Junglewise Threat Intelligence

CVE-2022-48285: Stuk JSZip path traversal in loadAsync

CVE-2022-48285 · Severity: low · CVSS 3.1 · Published 2023-01-29

Vendors: npm.

Executive brief

JSZip is a popular JavaScript library used to create, read, and edit ZIP files. A vulnerability in how it handles file names within archives could allow an attacker to perform a 'Zip Slip' attack. If an application uses this library to extract files, a specially crafted ZIP archive could write files to unintended locations on the system, potentially leading to data corruption or unauthorized access.

Technical details

A path traversal vulnerability exists in JSZip's loadAsync function prior to version 3.8.0. The library failed to properly sanitize filenames contained within ZIP archives, a flaw commonly known as 'Zip Slip.' An attacker can provide a crafted ZIP file containing filenames with traversal sequences (e.g., '../../etc/passwd'). When the library processes these files, it could allow an application to write data outside of the intended destination directory. This is reachable via any network vector where an application accepts and processes untrusted ZIP files using the affected library. The issue was fixed in version 3.8.0 by implementing filename sanitization and moving the original, potentially unsafe name to a new property called 'unsafeOriginalName'.

Affected products

  • Stuk jszip < 3.8.0

Timeline

  • 2022-03-30: patched: Fixed in version 3.8.0
  • 2023-01-29: disclosed: NVD publication date

References