sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, IO.unzip allows writing of arbitrary file. This would have potential to overwrite /root/.ssh/authorized_keys. Within sbt's main code, IO.unzip is used in pullRemoteCache task and Resolvers.remote; however many projects use IO.unzip(...) directly to implement custom tasks. This vulnerability has been patched in version 1.9.7.
{
"cwe_ids": [
"CWE-22"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46122.json",
"cna_assigner": "GitHub_M"
}{
"cpe": [
"cpe:2.3:a:scala-sbt:io:*:*:*:*:*:sbt:*:*",
"cpe:2.3:a:scala-sbt:sbt:*:*:*:*:*:*:*:*"
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.9.7"
},
{
"introduced": "0.3.4"
}
]
}