CVE-2023-22899 is a medium-severity vulnerability in Zip4j versions up to 2.11.2, affecting products like Threema, where the software fails to consistently verify the Message Authentication Code (MAC) during ZIP archive decryption. This flaw allows for a high-integrity impact without requiring user interaction, though it has a high attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.11.2CPE matchmatch criteria | cpe:2.3:a:zip4j_project:zip4j:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.