CVE-2023-22898

Publication date

2023-01-10 00:00:00

Family

mitre

State

PUBLISHED

Description

workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).