CVE-2022-25842 is a critical Arbitrary File Write vulnerability (Zip Slip) affecting all versions of the com.alibaba.oneagent:one-java-agent-plugin. This flaw allows an unauthenticated attacker to achieve remote command execution by uploading a specially crafted archive containing directory traversal filenames, overwriting executable files. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. While no active exploitation, public exploits (Metasploit, Nuclei, ExploitDB), or significant community discussion have been observed, its high FAUCET Risk Score of 82/100 warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:alibabagroup:one-java-agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.