CVE-2021-35515: Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
A flaw was found in apache-commons-compress. When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This flaw allows the mounting of a denial of service attack against services that use Compress' SevenZ package. The highest threat from this vulnerability is to system availability.
Other sources
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-35515.
What is the severity of CVE-2021-35515?
The severity of CVE-2021-35515 is high with a severity value of 7.5.
What is the affected software for CVE-2021-35515?
The affected software for CVE-2021-35515 includes Apache Commons Compress version up to and excluding 1.21, NetApp Active Iq Unified Manager, NetApp OnCommand Insight, Oracle Banking Digital Experience versions 18.1 to 18.3, and various other Oracle software.
What is the impact of CVE-2021-35515?
CVE-2021-35515 allows an attacker to mount a denial of service attack against services that use Compress' SevenZ package.
Is there a fix available for CVE-2021-35515?
Yes, the fix for CVE-2021-35515 is available in Apache Commons Compress version 1.20 and higher.