Infinite Loop Vulnerability in Apache Commons Compress
CVE-2024-25710
5.5MEDIUM
Summary
An infinite loop vulnerability exists in Apache Commons Compress, affecting versions from 1.3 through 1.25.0. This flaw could lead to applications becoming unresponsive, as the control flow may enter a loop with no reachable exit condition. Users are strongly advised to upgrade to version 1.26.0 or later, which addresses this issue and enhances overall security.
Affected Version(s)
Apache Commons Compress 1.3 <= 1.25.0
Get notified when SecurityVulnerability.io launches alerting 🔔
Well keep you posted 📧
News Articles

CVE-2024-25710 : APACHE COMMONS COMPRESS UP TO 1.25.0 INFINITE LOOP - Cloud WAF
CVE-2024-25710 : Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
- 📰
First article discovered by prophaze.com
Vulnerability published
Vulnerability Reserved
Credit
Yakov Shafranovich, Amazon Web Services