CVE-2018-10862: Red Hat JBoss Enterprise Application Platform
Medium severity, CVSS 5.5. EPSS: 1.3% chance of exploitation in the next 30 days.
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
Affected products
- Red Hat JBoss Enterprise Application Platform: version 7.1.0 only
- Red Hat Virtualization: version 4.0 only
- Red Hat Wildfly Core: up to and including 5.0.0; version 6.0.0 only
Published 2018-07-27. Last modified 2026-06-17.