Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78wr-2p64-hpwj

Опубликовано: 03 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Uncontrolled Resource Consumption vulnerability in Apache Commons IO.

The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.

This issue affects Apache Commons IO: from 2.0 before 2.14.0.

Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Пакеты

Наименование

commons-io:commons-io

maven
Затронутые версииВерсия исправления

>= 2.0, < 2.14.0

2.14.0

EPSS

Процентиль: 44%
0.00213
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 4.3
ubuntu
11 месяцев назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
redhat
11 месяцев назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
nvd
11 месяцев назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

msrc
10 месяцев назад

Описание отсутствует

CVSS3: 4.3
debian
11 месяцев назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. ...

EPSS

Процентиль: 44%
0.00213
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400