CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It affects Apache. Its EPSS score suggests a 16.2% probability of exploitation in the next 30 days. It may lead to a denial-of-service condition.
CVE
CVE-2019-12402
Severity
HIGH
CVSS
7.5
EPSS
16.16%
Apache
Original NVD Description
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
Related CVEs
Other vulnerabilities affecting the same vendor(s)