Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q62h-jw38-24vh

Опубликовано: 25 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Uncaught Exception in zip4j

zip4j up to 2.9.1 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.

Пакеты

Наименование

net.lingala.zip4j:zip4j

maven
Затронутые версииВерсия исправления

< 2.10.0

2.10.0

EPSS

Процентиль: 51%
0.00278
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-248
CWE-755

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.

CVSS3: 5.5
redhat
почти 4 года назад

zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.

CVSS3: 5.5
nvd
почти 4 года назад

zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.

CVSS3: 5.5
debian
почти 4 года назад

zip4j up to v2.10.0 can throw various uncaught exceptions while parsin ...

EPSS

Процентиль: 51%
0.00278
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-248
CWE-755