Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4265-ccf5-phj5

Опубликовано: 19 фев. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.7
CVSS3: 5.5

Описание

Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress. This issue affects Apache Commons Compress: from 1.21 before 1.26.

Users are recommended to upgrade to version 1.26, which fixes the issue.

Пакеты

Наименование

org.apache.commons:commons-compress

maven
Затронутые версииВерсия исправления

>= 1.21, < 1.26.0

1.26.0

EPSS

Процентиль: 63%
0.00448
Низкий

6.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.

CVSS3: 5.5
redhat
почти 2 года назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.

CVSS3: 5.5
nvd
почти 2 года назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.

msrc
5 месяцев назад

Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

CVSS3: 5.5
debian
почти 2 года назад

Allocation of Resources Without Limits or Throttling vulnerability in ...

EPSS

Процентиль: 63%
0.00448
Низкий

6.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-770