CVE-2022-21675 is an Arbitrary File Write vulnerability, also known as "Zip Slip," affecting Bytecode Viewer (BCV) versions prior to 2.11.0. An attacker can exploit this by crafting a malicious archive containing directory traversal filenames, leading to the overwriting of existing files or creation of new ones on the victim's system. With a CVSS score of 7.8 (HIGH), successful exploitation can result in remote command execution, for example, by placing a web shell in a web application's directory. While there is no evidence of active exploitation, public exploit code, or significant community discussion, immediate upgrade to BCV v2.11.0 is recommended as there are no other workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.10.16, < 2.11.0CPE matchmatch criteria | cpe:2.3:a:bytecode_viewer_project:bytecode_viewer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.