{"id":"GHSA-2pj2-gchf-wmw7","summary":"Zip4j Origin Validation Error","details":"Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive. This issue has been fixed in version 2.11.3.","aliases":["CVE-2023-22899"],"modified":"2023-11-08T04:11:39.466627Z","published":"2023-01-10T03:30:29Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-01-13T21:34:45Z","nvd_published_at":"2023-01-10T02:15:00Z","cwe_ids":["CWE-346"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-22899"},{"type":"WEB","url":"https://github.com/srikanth-lingala/zip4j/issues/485"},{"type":"WEB","url":"https://breakingthe3ma.app"},{"type":"WEB","url":"https://breakingthe3ma.app/files/Threema-PST22.pdf"},{"type":"PACKAGE","url":"https://github.com/srikanth-lingala/zip4j"},{"type":"WEB","url":"https://github.com/srikanth-lingala/zip4j/releases"},{"type":"WEB","url":"https://github.com/srikanth-lingala/zip4j/releases/tag/v2.11.3"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=34316206"},{"type":"WEB","url":"https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement"}],"affected":[{"package":{"name":"net.lingala.zip4j:zip4j","ecosystem":"Maven","purl":"pkg:maven/net.lingala.zip4j/zip4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.3"}]}],"versions":["1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.1","1.3.2","1.3.3","2.0","2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.10.0","2.11.0","2.11.1","2.11.2","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.3.0","2.3.1","2.3.2","2.4.0","2.5.0","2.5.1","2.5.2","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.7.0","2.8.0","2.9.0","2.9.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.11.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-2pj2-gchf-wmw7/GHSA-2pj2-gchf-wmw7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}