Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78wr-2p64-hpwj

Опубликовано: 03 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Uncontrolled Resource Consumption vulnerability in Apache Commons IO.

The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.

This issue affects Apache Commons IO: from 2.0 before 2.14.0.

Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Пакеты

Наименование

commons-io:commons-io

maven
Затронутые версииВерсия исправления

>= 2.0, < 2.14.0

2.14.0

EPSS

Процентиль: 66%
0.01241
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 2 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
redhat
почти 2 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
nvd
почти 2 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
msrc
больше 1 года назад

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

CVSS3: 4.3
debian
почти 2 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. ...

EPSS

Процентиль: 66%
0.01241
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400