CVE-2023-22899

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
References
Link Resource
https://breakingthe3ma.app Third Party Advisory
https://breakingthe3ma.app/files/Threema-PST22.pdf Exploit Technical Description Third Party Advisory
https://github.com/srikanth-lingala/zip4j/issues/485 Exploit Issue Tracking Patch Third Party Advisory
https://github.com/srikanth-lingala/zip4j/releases Release Notes Third Party Advisory
https://news.ycombinator.com/item?id=34316206 Third Party Advisory
https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zip4j_project:zip4j:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-01-10 02:15

Updated : 2024-02-28 19:51


NVD link : CVE-2023-22899

Mitre link : CVE-2023-22899

CVE.ORG link : CVE-2023-22899


JSON object : View

Products Affected

zip4j_project

  • zip4j
CWE
CWE-346

Origin Validation Error