A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to path traversal. Upgrading to version 0.5.2-pre2-alpha is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216747.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-36628.json"
[
{
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/calsign/apde/commit/c6d64cbe465348c1bfd211122d89e3117afadecf",
"digest": {
"threshold": 0.9,
"line_hashes": [
"246746123632485132447936165580281533111",
"220234041313732625573971515060463336741",
"229379629916021791409268426342367686473",
"191227737560376208574484726261697587771"
]
},
"target": {
"file": "APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java"
},
"signature_version": "v1",
"id": "CVE-2020-36628-4e75fc89"
},
{
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/calsign/apde/commit/c6d64cbe465348c1bfd211122d89e3117afadecf",
"digest": {
"length": 851.0,
"function_hash": "16989097847878197132046586987275620667"
},
"target": {
"function": "handleExtract",
"file": "APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java"
},
"signature_version": "v1",
"id": "CVE-2020-36628-edf3680e"
}
]