2.11.5
13 years ago
1 years ago
Known vulnerabilities in the net.lingala.zip4j:zip4j package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
net.lingala.zip4j:zip4j is an open source java library to handle zip files. Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity in that it does not always check the MAC when decrypting a ZIP archive. This allows attackers with knowledge of the filenames in use on the affected system, and write access to those files, to modify the contents of the archives without the changes being detected. How to fix Insufficient Verification of Data Authenticity? Upgrade | [0,2.11.3) |
net.lingala.zip4j:zip4j is an open source java library to handle zip files. Affected versions of this package are vulnerable to NULL Pointer Dereference. A How to fix NULL Pointer Dereference? Upgrade | [,2.7.0) |
net.lingala.zip4j:zip4j is an open source java library to handle zip files. Affected versions of this package are vulnerable to Insecure Randomness. Both How to fix Insecure Randomness? Upgrade | [,2.6.3) |
net.lingala.zip4j:zip4j is a open source java library to handle zip files. Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip). Successful exploitation of this vulnerability can result in remote command execution. How to fix Arbitrary File Write via Archive Extraction (Zip Slip)? Upgrade | [0,1.3.3) |