Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78wr-2p64-hpwj

Опубликовано: 03 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Uncontrolled Resource Consumption vulnerability in Apache Commons IO.

The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.

This issue affects Apache Commons IO: from 2.0 before 2.14.0.

Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Пакеты

Наименование

commons-io:commons-io

maven
Затронутые версииВерсия исправления

>= 2.0, < 2.14.0

2.14.0

EPSS

Процентиль: 39%
0.00173
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 1 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
redhat
больше 1 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
nvd
больше 1 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

msrc
около 1 года назад

Описание отсутствует

CVSS3: 4.3
debian
больше 1 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. ...

EPSS

Процентиль: 39%
0.00173
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400