Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pj2-gchf-wmw7

Опубликовано: 10 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Zip4j Origin Validation Error

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive. This issue has been fixed in version 2.11.3.

Пакеты

Наименование

net.lingala.zip4j:zip4j

maven
Затронутые версииВерсия исправления

<= 2.11.2

2.11.3

EPSS

Процентиль: 49%
0.0026
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 3 лет назад

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

CVSS3: 5.9
redhat
около 3 лет назад

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

CVSS3: 5.9
nvd
около 3 лет назад

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

CVSS3: 5.9
debian
около 3 лет назад

Zip4j through 2.11.2, as used in Threema and other products, does not ...

EPSS

Процентиль: 49%
0.0026
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-346