CVE-2024-5569

Aliases:GHSA-jfmj-5v4g-7637PYSEC-2026-2074RHSA-2024:9977DEBIAN-CVE-2024-5569CGA-32g4-mh4r-f2jrCGA-3389-mwg6-6vpxCGA-3jhm-3hfw-3m5hCGA-3m8f-94wx-hgj8CGA-42jf-wjwh-2chcCGA-56w3-6gjv-6rjrCGA-5f8h-f6cq-6hjqCGA-5xg7-r75h-v723CGA-6hwc-qcc8-r9wjCGA-7fqj-wc4h-hwc6CGA-7jm4-786j-v5pjCGA-7wwc-chvp-qcxvCGA-7x32-q85p-9rjgCGA-8hmm-7h92-x5mgCGA-9558-3g87-r6wjCGA-988x-c28v-7pgvCGA-f4j9-7fwv-j866CGA-fgq8-56qf-m845CGA-gp46-3639-68jgCGA-h5f6-95hc-fvxvCGA-jc3f-h5cr-pr4jCGA-mfp3-6cr4-x3c6CGA-mmfc-c8xg-86rxCGA-pf9q-jh83-rj66CGA-pjr5-34w3-2hhcCGA-pmwx-rvrq-p4r8CGA-q2p6-wj87-8xjrCGA-qcg5-w3hf-7c63CGA-qf8j-6jx9-98q5CGA-rr3g-gw84-4xw3CGA-v9fv-xvxw-fv8wCGA-vq54-gg7x-757cCGA-vrvc-89cx-rw9qCGA-w54j-8r9m-rqjfCGA-w7r8-w32j-3m5wCGA-wgrp-55wq-fjfxCGA-wgwh-2mf8-wp35CGA-wj9r-rrg2-rwf5CGA-xcrp-ffwx-jvx5CGA-xmcm-3p52-27cp
Deferred
Published: 09 Jul 2024, 00:00
Last modified:15 Oct 2025, 12:50

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.2 MEDIUM
v3.0 (cve.org)
EPSS Score
0.24% LOW
0% probability +0.22%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2024, 00:00
Published
Vulnerability first disclosed
15 Oct 2025, 12:50
Last Modified
Vulnerability information updated

Description

A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This issue also impacts the zipfile module of CPython, as features from the third-party zipp library are later merged into CPython, and the affected code is identical in both projects. The infinite loop can be initiated through the use of functions affecting the `Path` module in both zipp and zipfile, such as `joinpath`, the overloaded division operator, and `iterdir`. Although the infinite loop is not resource exhaustive, it prevents the application from responding. The vulnerability was addressed in version 3.19.1 of jaraco/zipp.

CVSS Metrics

  • v4.0MEDIUMScore: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v3.1MEDIUMScore: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.0MEDIUMScore: 6.2CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.24% Percentile: 15%

Techniques & Countermeasures

  • CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')

    The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Systems

  • chainguardcheckov

    < 3.0.34-r1

  • chainguardkubeflow-pipelines

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-apiserver

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-cache_server

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-cache-deployer

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-cache-deployer-compat

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-frontend

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-metadata-envoy-config

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-metadata-writer

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-metadata-writer-compat

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-persistence_agent

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-scheduledworkflow

    < 2.2.0-r7

  • chainguardkubeflow-pipelines-viewer-crd-controller

    < 2.2.0-r7

  • chainguardpy3-supported-zipp

    < 0

  • chainguardpy3-zipp

    < 0

  • chainguardpy3.10-zipp

    < 0

  • chainguardpy3.11-zipp

    < 0

  • chainguardpy3.12-zipp

    < 0

  • chainguardpy3.13-zipp

    < 0

  • chainguardsuperset

    < 4.0.2-r2

  • wolficheckov

    < 3.0.34-r1

  • wolfikubeflow-pipelines

    < 2.2.0-r7

  • wolfikubeflow-pipelines-apiserver

    < 2.2.0-r7

  • wolfikubeflow-pipelines-cache_server

    < 2.2.0-r7

  • wolfikubeflow-pipelines-cache-deployer

    < 2.2.0-r7

  • wolfikubeflow-pipelines-cache-deployer-compat

    < 2.2.0-r7

  • wolfikubeflow-pipelines-frontend

    < 2.2.0-r7

  • wolfikubeflow-pipelines-metadata-envoy-config

    < 2.2.0-r7

  • wolfikubeflow-pipelines-metadata-writer

    < 2.2.0-r7

  • wolfikubeflow-pipelines-metadata-writer-compat

    < 2.2.0-r7

  • wolfikubeflow-pipelines-persistence_agent

    < 2.2.0-r7

  • wolfikubeflow-pipelines-scheduledworkflow

    < 2.2.0-r7

  • wolfikubeflow-pipelines-viewer-crd-controller

    < 2.2.0-r7

  • wolfipy3-supported-zipp

    < 0

  • wolfipy3-zipp

    < 0

  • wolfipy3.10-zipp

    < 0

  • wolfipy3.11-zipp

    < 0

  • wolfipy3.12-zipp

    < 0

  • wolfipy3.13-zipp

    < 0

  • wolfisuperset

    < 4.0.2-r2

  • debianpython-zipp

    all | < 1.0.0-6+deb12u1 | < 3.19.2-1 | < 3.19.2-1

  • jaracojaraco/zipp

    ≥ unspecified, < 3.19.1

  • PyPIzipp

    < 3.19.1

  • redhatpython-zipp

    < 0:3.4.0-3.el9ost

  • redhatpython3-zipp

    < 0:3.4.0-3.el9ost

References (14)