Intel

CVE-2024-48510

DotNetZip is vulnerable to RCE

RCE Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 13, 2024

98

Critical Risk

This Affects:

DotNetZip
Are you affected? Scan for Free

TL;DR

A path traversal flag may lead to RCE

Who does this affect?

You're using any version of this package

Background info

DotNetZip is vulnerable to RCE in versions < 1.19.0.

How to fix this

This package is no longer maintained. Please transition to System.IO.Compression.