DotNetZip Directory Traversal vulnerability
        
  High severity
        
          GitHub Reviewed
      
        Published
          Nov 13, 2024 
          to the GitHub Advisory Database
          •
          Updated Nov 25, 2024 
      
  
Description
        Published by the National Vulnerability Database
      Nov 13, 2024 
    
  
        Published to the GitHub Advisory Database
      Nov 13, 2024 
    
  
        Reviewed
      Nov 13, 2024 
    
  
        Last updated
      Nov 25, 2024 
    
  
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component.
References