#VU80788 Resource exhaustion in Apache Commons Compress - CVE-2023-42503
Published: September 14, 2023 / Updated: December 22, 2023
Apache Commons Compress
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing .tar archives. A remote attacker can pass a specially crafted archive to the application and consume excessive CPU usage.