obiba / mica2

Mica is a web portal for epidemiological study consortia.
http://www.obiba.org/pages/products/mica/
GNU General Public License v3.0
10 stars 15 forks source link

CVE-2024-25710, CVE-2024-26308 #4446

Open mdc-webdb opened 6 months ago

mdc-webdb commented 6 months ago

This issue is unique

Version information

5.4.1

Expected behavior

No warning from the security scanner.

Actual behavior

The Apache Commons Compress library is prone to a denial of service (DoS) vulnerability.

Installed version: 1.25.0 Fixed version: 1.26.0 Installation path / port: /usr/share/mica2-5.4.1/webapp/WEB-INF/lib/commons-compress-1.25.0.jar

Reproduction steps

No response

Operating System (OS)

No response

Browser

No response

Contact info

No response