CVE-2018-10862: Red Hat JBoss Enterprise Application Platform

Medium severity, CVSS 5.5. EPSS: 1.3% chance of exploitation in the next 30 days.

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 7.1.0 only
  • Red Hat Virtualization: version 4.0 only
  • Red Hat Wildfly Core: up to and including 5.0.0; version 6.0.0 only

Published 2018-07-27. Last modified 2026-06-17.