CVE-2018-17297: Hutool
High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Affected products
- Hutool Hutool: before 4.1.12 (fixed in 4.1.12)
Published 2018-09-21. Last modified 2026-06-17.