CVE-2025-31672: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
PJ Fanning <[email protected]> Tue, 08 Apr 2025 10:44:37 +0000
| Newsgroups | gmane.comp.jakarta.poi.user |
|---|---|
| Message-ID | <[email protected]> |
Severity: moderate Affected versions: - Apache POI before 5.4.0 Description: Improper Input Validation vulnerability in Apache POI. The issue affects = the parsing of OOXML format files like xlsx, docx and pptx. These file = formats are basically zip files and it is possible for malicious users to = add zip entries with duplicate names (including the path) in the zip. In = this case, products reading the affected file could read different data = because 1 of the zip entries with the duplicate name is selected over = another but different products may choose a different zip entry. This issue affects Apache POI poi-ooxml before 5.4.0. poi-ooxml 5.4.0 has a= check that throws an exception if zip entries with duplicate file names = are found in the input file. Users are recommended to upgrade to version poi-ooxml 5.4.0, which fixes = the issue. Please read https://poi.apache.org/security.html for = recommendations about how to use the POI libraries securely. This issue is being tracked as bug-69620=20 References: https://bz.apache.org/bugzilla/show_bug.cgi?id=3D69620 https://poi.apache.org/ https://www.cve.org/CVERecord?id=3DCVE-2025-31672 https://issues.apache.org/jira/browse/bug-69620