CVE-2023-22899EPSS p44.9%
CVE-2023-22899CVE-2023-22899
zip4j_project / zip4j
Description
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
Scoring
| CVSS | 5.9 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
| EPSS | 0.62% probability of exploitation · percentile 44.9% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |