Описание
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
Ссылки
- Mailing ListVendor Advisory
- Mailing ListVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
7.5 High
CVSS3
5.3 Medium
CVSS3
Дефекты
Связанные уязвимости
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
Apache CXF allows unrestricted memory consumption in CXF HTTP clients
Уязвимость HTTP-клиента каркаса для веб-сервисов Apache CXF, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3
5.3 Medium
CVSS3