Severity
7.5
High severity
Details
- CVSS score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Overview
About vulnerability
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress’ sevenz package.Details
- Affected product:
- Apache Commons , Apache Hadoop , Apache Hive , Apache Lucene , Apache Spark , Apache Tapestry , Eclipse Jetty , Hibernate , Spring , agepredictor , avro , elasticsearch , gradle , infinispan , jarchivelib , jgit , logging-flume , logging-log4j2 , lucene , solr , tika , webdrivermanager
- Affected packages:
- trevni-doc @ 1.10.2 (+2332 more)