CVE-2023-22899: Medium severity zip4j vulnerability
Published Jan 10, 2023
·Updated
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
Affected Software
2 affected componentsFixes available
redhat/zip4j<2.11.3
2.11.3
Zip4j Project Zip4j<=2.11.2
Remediation
Patch Available
Event History
Jan 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-22899?
CVE-2023-22899 is a vulnerability in the Zip4j library, version 2.11.2 and earlier, which is used in Threema and other products. It allows an attacker to bypass MAC checks when decrypting a ZIP archive.
2
What is the severity of CVE-2023-22899?
CVE-2023-22899 has a severity rating of medium and a CVSS score of 5.9.
3
How does CVE-2023-22899 affect Zip4j and other products?
CVE-2023-22899 affects Zip4j version 2.11.2 and earlier, and any products that use this vulnerable version of Zip4j are also affected.
4
How can I fix CVE-2023-22899?
To fix CVE-2023-22899, you need to update Zip4j to version 2.11.3 or later.
5
What is the CWE category of CVE-2023-22899?
CVE-2023-22899 belongs to the CWE category 346: Origin Validation Error.