{"api_version":"v1","generated_at":"2026-10-07T13:25:00+00:00","product":{"cve_count":10,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-commons-compress-6353c178ac31","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Commons Compress","next_cursor":null,"observations":[{"affected":"1.3 \u2264 1.25.0","affected_versions_present":true,"cve_id":"CVE-2024-25710","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-25710","fixed":"See the Red Hat OpenShift serverless 1.33 documentation at: https://access.redhat.com/documentation/en-us/red_hat_openshift_serverless/1.33","last_modified":"2025-11-04T16:11:24.559Z","patch_url":"https://access.redhat.com/security/cve/CVE-2024-25710","primary_source":"","published":"2024-02-19T08:33:40.627Z"},{"affected":"1.21 < 1.26.0","affected_versions_present":true,"cve_id":"CVE-2024-26308","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-26308","fixed":"Install the latest version of the Migration Toolkit for Runtimes from the Red Hat catalog in the OperatorHub page within your OpenShift instance.","last_modified":"2025-03-27T19:10:43.565Z","patch_url":"https://access.redhat.com/security/cve/CVE-2024-26308","primary_source":"","published":"2024-02-19T08:31:50.192Z"},{"affected":"1.22 < 1.24.0","affected_versions_present":true,"cve_id":"CVE-2023-42503","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-42503","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:09:24.584Z","patch_url":"","primary_source":"","published":"2023-09-14T07:45:14.520Z"},{"affected":"Apache Commons Compress \u2264 1.20","affected_versions_present":true,"cve_id":"CVE-2021-36090","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-36090","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891","last_modified":"2024-08-04T00:47:43.813Z","patch_url":"https://access.redhat.com/security/cve/CVE-2021-36090","primary_source":"","published":"2021-07-13T07:15:23.000Z"},{"affected":"1.1 < Apache Commons Compress*","affected_versions_present":true,"cve_id":"CVE-2021-35517","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-35517","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891","last_modified":"2024-08-04T00:40:46.713Z","patch_url":"https://access.redhat.com/security/cve/CVE-2021-35517","primary_source":"","published":"2021-07-13T07:15:22.000Z"},{"affected":"1.6 < Apache Commons Compress*","affected_versions_present":true,"cve_id":"CVE-2021-35516","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-35516","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891","last_modified":"2024-08-04T00:40:46.628Z","patch_url":"https://access.redhat.com/security/cve/CVE-2021-35516","primary_source":"","published":"2021-07-13T07:15:20.000Z"},{"affected":"1.6 < Apache Commons Compress*","affected_versions_present":true,"cve_id":"CVE-2021-35515","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-35515","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891","last_modified":"2024-08-04T00:40:47.264Z","patch_url":"https://access.redhat.com/security/cve/CVE-2021-35515","primary_source":"","published":"2021-07-13T07:15:19.000Z"},{"affected":"1.15 to 1.18","affected_versions_present":true,"cve_id":"CVE-2019-12402","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-12402","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T23:17:39.992Z","patch_url":"","primary_source":"","published":"2019-08-29T00:00:00.000Z"},{"affected":"1.7 to 1.17","affected_versions_present":true,"cve_id":"CVE-2018-11771","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-11771","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T22:03:17.708Z","patch_url":"https://www.oracle.com/security-alerts/cpujan2022.html","primary_source":"","published":"2018-08-16T15:00:00.000Z"},{"affected":"1.11 to 1.15","affected_versions_present":true,"cve_id":"CVE-2018-1324","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1324","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T03:59:32.872Z","patch_url":"https://www.oracle.com/security-alerts/cpujan2022.html","primary_source":"","published":"2018-03-16T13:00:00.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Apache Software Foundation"}}
