Lucene search

K
f5F5F5:K000133710
HistoryApr 28, 2023 - 12:00 a.m.

K000133710 : apache-commons-compress vulnerability CVE-2021-36090

2023-04-2800:00:00
my.f5.com
8
security advisory
denial of service
zip archive
out of memory error
f5 products
software vulnerability

6.6 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.1%

Security Advisory Description

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress’ zip package. (CVE-2021-36090)

Impact

There is no impact; F5 products are not affected by this vulnerability.

6.6 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.1%