CVE-2022-24615: Medium severity zip4j vulnerability
zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24615?
CVE-2022-24615 is a vulnerability in the zip4j library up to version 2.10.0 that can result in an application crash due to uncaught exceptions while parsing a specially crafted ZIP file.
What is the severity of CVE-2022-24615?
CVE-2022-24615 has a severity rating of 5.5 (medium).
How does CVE-2022-24615 affect zip4j?
CVE-2022-24615 affects zip4j up to version 2.10.0, where it can throw uncaught exceptions while parsing a specially crafted ZIP file.
How can CVE-2022-24615 be exploited?
CVE-2022-24615 could be exploited by creating a specially crafted ZIP file that triggers the uncaught exceptions in zip4j, potentially leading to an application crash.
Is there a fix available for CVE-2022-24615?
Currently, there is no fix available for CVE-2022-24615. It is recommended to update to a version of zip4j that is not affected by this vulnerability when one becomes available.