Lucene search

K
redhatcveRedhat.comRH:CVE-2019-12402
HistoryDec 29, 2019 - 9:46 a.m.

CVE-2019-12402

2019-12-2909:46:38
redhat.com
access.redhat.com
12

0.005 Low

EPSS

Percentile

76.3%

A resource consumption vulnerability was discovered in apache-commons-compress in the way NioZipEncoding encodes filenames. Applications that use Compress to create archives, with one of the filenames within the archive being controlled by the user, may be vulnerable to this flaw. A remote attacker could exploit this flaw to cause an infinite loop during the archive creation, thus leading to a denial of service.