PT-2021-3993 · Apache+4 · Apache Commons Compress+4

Oss Fuzz

·

Published

2021-07-13

·

Updated

2024-08-06

·

CVE-2021-35515

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Commons Compress versions prior to the fixed version Confluence Data Center versions from 7.19.23 through 8.9.3 Confluence Data Center versions from 8.5.10 through 8.5.11 Confluence Server versions from 7.19.23 through 7.19.24 Confluence Server versions from 8.5.10 through 8.5.11
Description The issue is related to the construction of the list of codecs that decompress an entry in a specially crafted 7Z archive, which can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. An unauthenticated attacker can expose assets in the environment susceptible to exploitation, with no impact to confidentiality, no impact to integrity, and high impact to availability, requiring no user interaction.
Recommendations For Confluence Data Center versions from 8.9.2 to 8.9.3, upgrade to version 8.9.4. For Confluence Data Center versions from 8.5.10 to 8.5.11, upgrade to version 8.9.4 or 8.5.12. For Confluence Data Center versions from 7.19.23 to 7.19.24, upgrade to version 8.9.4, 8.5.12, or 7.19.25. For Confluence Server versions from 8.5.10 to 8.5.11, upgrade to version 8.5.12. For Confluence Server versions from 7.19.23 to 7.19.24, upgrade to version 8.5.12 or 7.19.25. As a temporary workaround, consider restricting access to the sevenz package until a patch is available.

Exploit

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

AZL-45081
BDU:2021-04515
CVE-2021-35515
GHSA-7HFM-57QF-J43Q
MGASA-2022-0009
OESA-2021-1302
OPENSUSE-SU-2021:1115-1
OPENSUSE-SU-2021:2612-1
OPENSUSE-SU-2021_1115-1
OPENSUSE-SU-2021_2612-1
OPENSUSE-SU-2024:10618-1
RHSA-2022:5555
SUSE-SU-2021:2612-1
SUSE-SU-2021_2612-1

Affected Products

Apache Commons Compress
Confluence
Debian
Red Os
Suse