Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-23520

The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a ZipFile object.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.8%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 7.5
Products affected by CVE-2021-23520
  • Juce » Juce » Version: Any
    cpe:2.3:a:juce:juce:*


Contact Us

Shodan ® - All rights reserved