CVE-2024-8088
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-8088 is a high-severity vulnerability found in the CPython "zipfile" module, specifically affecting the methods of "zipfile.Path" like "namelist()" and "iterdir()". When processing maliciously crafted zip archives, this vulnerability can lead to an infinite loop during metadata reading or content extraction. The unaffected class is "zipfile.ZipFile". To mitigate this risk, it is recommended that organizations avoid handling user-controlled zip archives when using affected products, which include various versions of CPython-related applications. The vulnerability poses a significant risk as it can lead to high availability impact, potentially disrupting services reliant on these processes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.