5.9
CVSSv3

CVE-2023-22899

Published: 10/01/2023 Updated: 30/01/2023
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

Zip4j up to and including 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zip4j project zip4j

Vendor Advisories

Debian Bug report logs - #1029038 zip4j: CVE-2023-22899 Package: src:zip4j; Maintainer for src:zip4j is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 16 Jan 2023 19:33:05 UTC Severity: important Tags: security, upstream Fixed in ve ...
Synopsis Important: Migration Toolkit for Applications security and bug fix update Type/Severity Security Advisory: Important Topic Migration Toolkit for Applications 620 releaseRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a deta ...
Synopsis Moderate: Migration Toolkit for Runtimes security update Type/Severity Security Advisory: Moderate Topic An update is now available for Migration Toolkit for RuntimesRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed ...