PT-2021-3725 · Apache+4 · Apache Commons Compress+4

Published

2021-07-13

·

Updated

2024-08-06

·

CVE-2021-35516

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Commons Compress versions 1.19 through 1.21 Apache Commons Compress version 1.22 Confluence Data Center versions from 7.19.23 to 8.9.3 Confluence Data Center versions from 8.5.10 to 8.5.11 Confluence Server versions from 7.19.23 to 7.19.24 Confluence Server versions from 8.5.10 to 8.5.11
Description The issue is related to errors when processing input data length parameters in the sevenz package of Apache Commons Compress. This could allow a remote attacker to cause a denial of service by allocating large amounts of memory, leading to an out of memory error even with small inputs. The vulnerability can be exploited to mount a denial of service attack against services using Compress' sevenz package.
Recommendations For Confluence Data Center versions from 8.9.2 to 8.9.3, upgrade to version 8.9.4. For Confluence Data Center versions from 8.5.10 to 8.5.11 LTS, upgrade to version 8.9.4 or 8.5.12 LTS. For Confluence Data Center versions from 7.19.23 to 7.19.24 LTS, upgrade to version 8.9.4 or 8.5.12 LTS or 7.19.25 LTS. For Confluence Server versions from 8.5.10 to 8.5.11 LTS, upgrade to version 8.5.12 LTS. For Confluence Server versions from 7.19.23 to 7.19.24 LTS, upgrade to version 8.5.12 LTS or 7.19.25 LTS. As a temporary workaround, consider restricting the use of the sevenz package in Apache Commons Compress to minimize the risk of exploitation.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

AZL-45144
BDU:2021-03965
CVE-2021-35516
GHSA-CRV7-7245-F45F
MGASA-2022-0009
OESA-2021-1302
OPENSUSE-SU-2021:1115-1
OPENSUSE-SU-2021:2612-1
OPENSUSE-SU-2021_1115-1
OPENSUSE-SU-2021_2612-1
OPENSUSE-SU-2024:10618-1
RHSA-2022:5555
SUSE-SU-2021:2612-1

Affected Products

Apache Commons Compress
Confluence
Debian
Red Os
Suse