Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.
{ "nvd_published_at": "2022-11-15T01:15:00Z", "github_reviewed_at": "2022-11-21T23:49:10Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-22" ] }