{"id":"GHSA-23gj-368h-92pq","summary":"Path Traversal in DKPro Core","details":"core/api/datasets/internal/actions/Explode.java in the Dataset API in DKPro Core through 1.10.0 allows Directory Traversal, resulting in the overwrite of local files with the contents of an archive.","aliases":["CVE-2019-11082"],"modified":"2023-11-08T04:00:59.740037Z","published":"2019-05-29T18:05:11Z","database_specific":{"nvd_published_at":"2019-05-10T16:29:00Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2019-05-16T15:34:40Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11082"},{"type":"WEB","url":"https://github.com/dkpro/dkpro-core/issues/1325"}],"affected":[{"package":{"name":"de.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl","ecosystem":"Maven","purl":"pkg:maven/de.tudarmstadt.ukp.dkpro.core/de.tudarmstadt.ukp.dkpro.core.api.datasets-asl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.10.0"}]}],"versions":["1.10.0","1.9.0","1.9.1","1.9.2","1.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-23gj-368h-92pq/GHSA-23gj-368h-92pq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}