Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78wr-2p64-hpwj

Опубликовано: 03 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Uncontrolled Resource Consumption vulnerability in Apache Commons IO.

The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.

This issue affects Apache Commons IO: from 2.0 before 2.14.0.

Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Пакеты

Наименование

commons-io:commons-io

maven
Затронутые версииВерсия исправления

>= 2.0, < 2.14.0

2.14.0

EPSS

Процентиль: 14%
0.00046
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 4.3
ubuntu
9 месяцев назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
redhat
9 месяцев назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
nvd
9 месяцев назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

msrc
7 месяцев назад

Описание отсутствует

CVSS3: 4.3
debian
9 месяцев назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. ...

EPSS

Процентиль: 14%
0.00046
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400