Vulnerability Description
workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Circl | Pandora | < 1.3.1 |
Related Weaknesses (CWE)
References
- https://github.com/pandora-analysis/pandora/commit/1dc06327fdc07c56eae653e497dd1PatchThird Party Advisory
- https://github.com/pandora-analysis/pandora/commit/1dc06327fdc07c56eae653e497dd1PatchThird Party Advisory
FAQ
What is CVE-2023-22898?
CVE-2023-22898 is a vulnerability with a CVSS score of 6.5 (MEDIUM). workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).
How severe is CVE-2023-22898?
CVE-2023-22898 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22898?
Check the references section above for vendor advisories and patch information. Affected products include: Circl Pandora.