Lucene search

K
vulnrichmentApacheVULNRICHMENT:CVE-2024-26308
HistoryFeb 19, 2024 - 8:31 a.m.

CVE-2024-26308 Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

2024-02-1908:31:50
CWE-770
apache
github.com
commons compress
outofmemoryerror
pack200
apache
upgrade
vulnerability
version 1.26
allocation of resources

6.7 Medium

AI Score

Confidence

Low

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26.

Users are recommended to upgrade to version 1.26, which fixes the issue.

CNA Affected

[
  {
    "vendor": "Apache Software Foundation",
    "product": "Apache Commons Compress",
    "versions": [
      {
        "status": "affected",
        "version": "1.21",
        "lessThan": "1.26.0",
        "versionType": "semver"
      }
    ],
    "packageName": "org.apache.commons:commons-compress",
    "collectionURL": "https://repo.maven.apache.org/maven2/",
    "defaultStatus": "unaffected"
  }
]