Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-25710, CVE-2024-26308 #4446

Open
1 task done
mdc-webdb opened this issue Apr 2, 2024 · 0 comments
Open
1 task done

CVE-2024-25710, CVE-2024-26308 #4446

mdc-webdb opened this issue Apr 2, 2024 · 0 comments
Assignees
Labels

Comments

@mdc-webdb
Copy link

This issue is unique

  • I have used the search tool and did not find an issue describing my bug.

Version information

5.4.1

Expected behavior

No warning from the security scanner.

Actual behavior

The Apache Commons Compress library is prone to a denial of service (DoS) vulnerability.

Installed version: 1.25.0
Fixed version: 1.26.0
Installation
path / port: /usr/share/mica2-5.4.1/webapp/WEB-INF/lib/commons-compress-1.25.0.jar

Reproduction steps

No response

Operating System (OS)

No response

Browser

No response

Contact info

No response

@mdc-webdb mdc-webdb added the bug label Apr 2, 2024
@mdc-webdb mdc-webdb changed the title CVE-2024-25710 CVE-2024-25710, CVE-2024-26308 Apr 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants