Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-22899

Опубликовано: 10 янв. 2023
Источник: redhat
CVSS3: 5.9

Описание

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

A flaw was found in Zip4j. In this issue, it does not always check the MAC when decrypting a ZIP archive.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7org.drools-droolsjbpm-integrationOut of support scope
Migration Toolkit for Runtimes 1 on RHEL 8org.jboss.windup-windup-parentFixedRHSA-2023:381427.06.2023
MTA-6.2-RHEL-9mta/mta-operator-bundleFixedRHSA-2023:462714.08.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2185278zip4j: does not always check the MAC when decrypting a ZIP archive

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 3 лет назад

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

CVSS3: 5.9
nvd
около 3 лет назад

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

CVSS3: 5.9
debian
около 3 лет назад

Zip4j through 2.11.2, as used in Threema and other products, does not ...

CVSS3: 5.9
github
около 3 лет назад

Zip4j Origin Validation Error

5.9 Medium

CVSS3