CVE-2018-11771 is a denial-of-service vulnerability affecting Apache Commons Compress versions 1.7 to 1.17, as well as Oracle WebLogic Server, where a specially crafted ZIP archive can cause an infinite stream when processed by ZipArchiveInputStream combined with java.io.InputStreamReader. This vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and local attack vector, but a high impact on availability. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.7.0, <= 1.17.0CPE matchmatch criteria | cpe:2.3:a:apache:commons_compress:*:*:*:*:*:*:*:* | ||
14.1.1.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.