Lucene search

K
githubGitHub Advisory DatabaseGHSA-2PJ2-GCHF-WMW7
HistoryJan 10, 2023 - 3:30 a.m.

Zip4j Origin Validation Error

2023-01-1003:30:29
CWE-346
GitHub Advisory Database
github.com
14
zip4j
mac validation
threema
software security

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

50.9%

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive. This issue has been fixed in version 2.11.3.

Affected configurations

Vulners
Node
net.lingala.zip4jzip4jRange2.11.2
VendorProductVersionCPE
net.lingala.zip4jzip4j*cpe:2.3:a:net.lingala.zip4j:zip4j:*:*:*:*:*:*:*:*

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

50.9%