Vulnerability CVE-2025-67030: Information
Description
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
Severity: HIGH (8.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| kafka | sisyphus | 4.2.0-alt2 | 4.2.0-alt4 | ALT-PU-2026-5782-1 | 414376 | Fixed |
| kafka | sisyphus_loongarch64 | 4.2.0-alt3 | 4.2.0-alt4 | ALT-PU-2026-5915-1 | - | Fixed |
| kafka | c10f2 | 4.2.0-alt3 | 3.9.1-alt2.c10.1 | ALT-PU-2026-5788-1 | 414377 | Testing |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
|---|---|
| https://gist.github.com/weaver4VD/3216dac645220f8c9b488362f61241ec |
|
| https://github.com/codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d29547e0012d5b29642 |
|
| https://github.com/codehaus-plexus/plexus-utils/issues/294 |
|
| https://github.com/codehaus-plexus/plexus-utils/pull/295 |
|
| https://github.com/codehaus-plexus/plexus-utils/pull/296 |
|
| GHSA-6fmv-xxpf-w3cw |