Lucene search

K
redhatcveRedhat.comRH:CVE-2023-22899
HistoryApr 07, 2023 - 6:59 p.m.

CVE-2023-22899

2023-04-0718:59:36
redhat.com
access.redhat.com
17
zip4j
flaw
mac
decrypting
zip archive

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

50.9%

A flaw was found in Zip4j. In this issue, it does not always check the MAC when decrypting a ZIP archive.

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

50.9%