CVE-2024-8088

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Aug 22, 2024
Updated: Aug 26, 2024
CWE ID 835

Summary

CVE-2024-8088 is a high-severity vulnerability found in the CPython "zipfile" module, specifically affecting the methods of "zipfile.Path" like "namelist()" and "iterdir()". When processing maliciously crafted zip archives, this vulnerability can lead to an infinite loop during metadata reading or content extraction. The unaffected class is "zipfile.ZipFile". To mitigate this risk, it is recommended that organizations avoid handling user-controlled zip archives when using affected products, which include various versions of CPython-related applications. The vulnerability poses a significant risk as it can lead to high availability impact, potentially disrupting services reliant on these processes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share