commons-asic is vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)
40
Medium Risk
Affected versions of this package lack proper ZipBomb protection, failing to enforce size limits on meta-inf files during extraction. An attacker can exploit this vulnerability by crafting a malicious ZIP archive containing excessively large meta-inf files, which, when processed, overwhelms system resources (e.g., disk space or memory) due to uncontrolled extraction.
You are affected if you are using a version that falls within the vulnerable range.
commons-asic is vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) in versions 0.9.4 - 1.0.0.
Upgrade the no.difi.commons:commons-asic library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant