Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2023-22899 - CERT CVE
CVE-2023-22899
ID
CVE-2023-22899
Sažetak
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
Reference
https://breakingthe3ma.app
https://breakingthe3ma.app/files/Threema-PST22.pdf
https://github.com/srikanth-lingala/zip4j/issues/485
https://github.com/srikanth-lingala/zip4j/releases
https://news.ycombinator.com/item?id=34316206
https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement
https://breakingthe3ma.app
https://breakingthe3ma.app/files/Threema-PST22.pdf
https://github.com/srikanth-lingala/zip4j/issues/485
https://github.com/srikanth-lingala/zip4j/releases
https://news.ycombinator.com/item?id=34316206
https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement
CVSS
Base:
5.9
Impact:
3.6
Exploitability:
2.2
Pristup
Vektor
Složenost
Autentikacija
NETWORK
HIGH
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
NONE
HIGH
NONE
CVSS vektor
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Zadnje važnije ažuriranje
09-04-2025 - 16:15
Objavljeno
10-01-2023 - 02:15