{ "schema_version": "1.4.0", "id": "GHSA-p5gc-65fr-7vfc", "modified": "2023-01-31T12:30:24Z", "published": "2023-01-31T12:30:24Z", "aliases": [ "CVE-2023-0592" ], "details": "A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attackers could force jefferson to write outside of the extraction directory.This issue affects jefferson: before 0.4.1.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0592" }, { "type": "WEB", "url": "https://github.com/sviehb/jefferson/commit/971aca1a8b3b9f4fcb4674fa9621d3349195cdc6" }, { "type": "WEB", "url": "https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk" } ], "database_specific": { "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-01-31T10:15:00Z" } }