Описание
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.
Ссылки
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:apache:ws-xmlrpc:3.1.3:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.0114
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-400
Связанные уязвимости
CVSS3: 5
redhat
больше 9 лет назад
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.
EPSS
Процентиль: 78%
0.0114
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-400