The vendor explicitly states that these products are not affected by this CVE.
- 3scale-amp2/backend-rhel8 as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp2/system-rhel8 as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp2/system-rhel9 as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp2/toolbox-rhel9 as a component of Red Hat 3scale API Management Platform 2
- Summary
- A flaw was found in rubyzip. This path traversal vulnerability in the Zip::Entry#extract function allows a remote attacker to craft malicious archive entries. By failing to properly validate extraction paths, the vulnerability enables an attacker to write files outside the intended extraction directory, potentially leading to arbitrary file write.
- Remediation
- No remediation text is recorded.
