CVE-2026-2818 - CERT CVE
ID CVE-2026-2818
Sažetak A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
Reference
CVSS
Base: 8.2
Impact: 4.7
Exploitability:2.8
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW HIGH NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Zadnje važnije ažuriranje 20-02-2026 - 18:57
Objavljeno 20-02-2026 - 17:25