<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:03:43.109779+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-192034</id>
    <title>EUVD-2026-192034</title>
    <updated>2026-10-02T20:03:43.185509+00:00</updated>
    <content>EUVD-2026-192034</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-192034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-37460</id>
    <title>fkie_cve-2023-37460</title>
    <updated>2026-10-02T20:03:43.185552+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting an archive with an entry that already exists in the destination directory as a symbolic link whose target does not exist - the `resolveFile()` function will return the symlink's source instead of its target, which will pass the verification that ensures the file will not be extracted outside of the destination directory. Later `Files.newOutputStream()`, that follows symlinks by default,  will actually write the entry's content to the symlink's target. Whoever uses plexus archiver to extract an untrusted archive is vulnerable to an arbitrary file creation and possibly remote code execution. Version 4.8.0 contains a patch for this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-37460"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wh3p-fphp-9h2m</id>
    <title>GHSA-wh3p-fphp-9h2m — Arbitrary File Creation in AbstractUnArchiver</title>
    <updated>2026-10-02T20:03:43.185592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.codehaus.plexus:plexus-archiver</p>
<p>### Summary</p>
<p>Using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution.</p>
<p>### Description
When extracting an archive with an entry that already exists in the destination directory as a symbolic link whose target does not exist - the resolveFile() function will return the symlink's source instead of its target, which will pass the verification that ensures the file will not be extracted outside of the destination directory. Later Files.newOutputStream(), that follows symlinks by default,  will actually write the entry's content to the symlink's target.</p>
<p>### Impact
Whoever uses plexus archiver to extract an untrusted archive is vulnerable to an arbitrary file creation and possibly remote code execution.</p>
<p>### Technical Details</p>
<p>In [AbstractUnArchiver.java](https://github.com/codehaus-plexus/plexus-archiver/blob/plexus-archiver-4.7.1/src/main/java/org/codehaus/plexus/archiver/AbstractUnArchiver.java#L342):
```java
protected void extractFile( final File srcF, final File dir, final InputStream compressedInputStream, String entryName, final Date entryDate, final boolean isDirectory, final Integer mode, String symlinkDestination, final FileMapper[] fileMappers)
    throws IOException, ArchiverException
    {
        ...
        // Hmm. Symlinks re-evaluate back to the original file here. Unsure if this is a good thing...
        final File targetFileName = FileUtils.resolveFile( dir, entryName );</p>
<p>// Make s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wh3p-fphp-9h2m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-37460</id>
    <title>gsd-2023-37460</title>
    <updated>2026-10-02T20:03:43.185660+00:00</updated>
    <content>gsd-2023-37460</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-37460"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-37460</id>
    <title>msrc_CVE-2023-37460 — Plexus Archiver vulnerable to Arbitrary File Creation in AbstractUnArchiver</title>
    <updated>2026-10-02T20:03:43.185674+00:00</updated>
    <content>msrc_CVE-2023-37460</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-37460"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1670</id>
    <title>OESA-2025-1670 — plexus-archiver security update</title>
    <updated>2026-10-02T20:03:43.185689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: plexus-archiver</p>
<p>The Plexus project provides a full software stack for creating and executing software projects. It provides a number of pre-built components for common tasks and toolkits such as Jetty, Velocity, Hibernate, i18n, and many more. However, Plexus is also able to reuse your existing components written for other IoC frameworks such as Spring, Avalon and Pico Container unmodified, as well as allowing you to reuse your existing code inside the Plexus Container.

Security Fix(es):</p>
<p>Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting an archive with an entry that already exists in the destination directory as a symbolic link whose target does not exist - the `resolveFile()` function will return the symlink&amp;apos;s source instead of its target, which will pass the verification that ensures the file will not be extracted outside of the destination directory. Later `Files.newOutputStream()`, that follows symlinks by default,  will actually write the entry&amp;apos;s content to the symlink&amp;apos;s target. Whoever uses plexus archiver to extract an untrusted archive is vulnerable to an arbitrary file creation and possibly remote code execution. Version 4.8.0 contains a patch for this issue.(CVE-2023-37460)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13309-1</id>
    <title>openSUSE-SU-2024:13309-1 — plexus-archiver-4.8.0-2.1 on GA media</title>
    <updated>2026-10-02T20:03:43.185719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>plexus-archiver-4.8.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13309-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:6138</id>
    <title>RHSA-2023:6138 — Red Hat Security Advisory: Migration Toolkit for Runtimes security update</title>
    <updated>2026-10-02T20:03:43.185735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>plexus-archiver: Arbitrary File Creation in AbstractUnArchiver</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:6138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-37460</id>
    <title>UBUNTU-CVE-2023-37460</title>
    <updated>2026-10-02T20:03:43.185749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: plexus-archiver, Ubuntu:16.04:LTS: plexus-archiver, Ubuntu:Pro:18.04:LTS: plexus-archiver, Ubuntu:20.04:LTS: plexus-archiver, Ubuntu:22.04:LTS: plexus-archiver, Ubuntu:24.04:LTS: plexus-archiver, Ubuntu:25.10: plexus-archiver, Ubuntu:26.04:LTS: plexus-archiver</p>
<p>Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting an archive with an entry that already exists in the destination directory as a symbolic link whose target does not exist - the `resolveFile()` function will return the symlink's source instead of its target, which will pass the verification that ensures the file will not be extracted outside of the destination directory. Later `Files.newOutputStream()`, that follows symlinks by default,  will actually write the entry's content to the symlink's target. Whoever uses plexus archiver to extract an untrusted archive is vulnerable to an arbitrary file creation and possibly remote code execution. Version 4.8.0 contains a patch for this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-37460"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2368</id>
    <title>WID-SEC-W-2023-2368 — IBM Operational Decision Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:03:43.185783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter authentifizierter Angreifer kann mehrere Schwachstellen in IBM Operational Decision Manager ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2368"/>
  </entry>
</feed>
