CVE-2023-22899

5.9MEDIUM

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

Published: 1/10/2023Updated: 4/9/2025

Description

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

AI AnalysisPowered by AI

Affected Products

zip4j_projectzip4j

References