Infinite Loop Vulnerability in Apache Commons Compress
CVE-2024-25710
8.1HIGH
What is CVE-2024-25710?
An infinite loop vulnerability exists in Apache Commons Compress, affecting versions from 1.3 through 1.25.0. This flaw could lead to applications becoming unresponsive, as the control flow may enter a loop with no reachable exit condition. Users are strongly advised to upgrade to version 1.26.0 or later, which addresses this issue and enhances overall security.
Affected Version(s)
Apache Commons Compress 1.3 <= 1.25.0
News Articles
CVE-2024-25710 : APACHE COMMONS COMPRESS UP TO 1.25.0 INFINITE LOOP - Cloud WAF
CVE-2024-25710 : Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
- đź“°
First article discovered by prophaze.com
Vulnerability published
Vulnerability Reserved
Credit
Yakov Shafranovich, Amazon Web Services