CVE-2025-67030

NameCVE-2025-67030
DescriptionDirectory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1132326

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
plexus-utils2 (PTS)bullseye3.3.0-1vulnerable
forky, sid, bookworm, trixie3.4.2-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
plexus-utils2source(unstable)(unfixed)1132326

Notes

[trixie] - plexus-utils2 <no-dsa> (Minor issue)
[bookworm] - plexus-utils2 <no-dsa> (Minor issue)
[bullseye] - plexus-utils2 <postponed> (Minor issue)
https://github.com/codehaus-plexus/plexus-utils/issues/294
https://github.com/codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d29547e0012d5b29642 (plexus-utils-4.0.3)
https://github.com/codehaus-plexus/plexus-utils/commit/36ea3526309d2842075bf018d45152816a37fc98 (plexus-utils-3.x)

Search for package or bug name: Reporting problems