Appsecure logo

CVE-2023-42503: Medium Vulnerability in Apache Commons Compress

A medium severity vulnerability has been identified in Apache Commons Compress, affecting versions from 1.22 prior to 1.24.0. This vulnerability allows attackers to create malformed TAR files, leading to uncontrolled resource consumption. Immediate patching is recommended.

MEDIUMCVSS 5.5 · Published September 14, 2023

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2023-42503 identifies a medium severity vulnerability in Apache Commons Compress, specifically related to improper input validation and uncontrolled resource consumption during TAR parsing. This vulnerability affects users of Apache Commons Compress from version 1.22 up to, but not including, version 1.24.0. The issue arises when a third party crafts a malformed TAR file by manipulating file modification time headers, leading to a denial of service (DoS) via excessive CPU consumption.

The vulnerability leverages the parsing of file modification times with high precision, which was introduced in version 1.22. The impacted fields include 'atime', 'ctime', 'mtime', and 'LIBARCHIVE.creationtime'. Notably, no input validation occurs before the parsing of these header values. This flaw allows attackers to exploit the algorithmic complexity issue in the BigDecimal class, leading to prolonged CPU processing times that can significantly hinder application performance.

Organizations should prioritize patching to version 1.24.0 or later as this update resolves the identified vulnerabilities. Failure to address this issue may expose systems to potential denial of service attacks, impacting availability.

With a CVSS score of 5.5, this vulnerability is categorized as medium severity, indicating that while it may not be immediately critical, the risks to organizations include significant service interruptions and resource exhaustion, especially in environments where TAR file parsing is frequent.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.