QID 981071
QID 981071: Java (maven) Security Update for org.apache.commons:commons-compress (GHSA-h436-432x-8fvx)
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h436-432x-8fvx for updates pertaining to this vulnerability.
Vendor References
- GHSA-h436-432x-8fvx -
github.com/advisories/GHSA-h436-432x-8fvx
CVEs related to QID 981071
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h436-432x-8fvx | org.apache.commons:commons-compress |
|