cbcvebase.
CVE-2021-36090
published 2021-07-13

CVE-2021-36090: When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

Affected

70 ranges· showing 25
VendorProductVersion rangeFixed in
apachecommons_compress>= 1.0 < 1.211.21
apache_software_foundationapache_commons_compressApache Commons Compress – 1.20
atlassianconfluence_data_center
debianlibcommons-compress-java< libcommons-compress-java 1.21-1 (bookworm)libcommons-compress-java 1.21-1 (bookworm)
oraclebanking_apis
oraclebanking_apis
oraclebanking_apis
oraclebanking_apis
oraclebanking_apis18.1 – 18.3
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience18.1 – 18.3
oraclebanking_enterprise_default_management
oraclebanking_party_management
oraclebanking_payments
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_trade_finance
oraclebanking_treasury_management
oraclebusiness_process_management_suite
oraclebusiness_process_management_suite

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH