Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-26308

Опубликовано: 19 фев. 2024
Источник: redhat
CVSS3: 5.5

Описание

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.

An allocation of resources without limits or throttling vulnerability was found in Apache Commons Compress. This issue can lead to an out-of-memory error.

Меры по смягчению последствий

No mitigation is currently available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
AMQ Clientscommons-compressNot affected
A-MQ Clients 2commons-compressNot affected
Cryostat 2commons-compressFix deferred
Logging Subsystem for Red Hat OpenShiftorg.elasticsearch-elasticsearchNot affected
Red Hat Ansible Automation Platform 2commons-compressWill not fix
Red Hat build of Apache Camel for Spring Boot 3commons-compressNot affected
Red Hat build of Apache Camel for Spring Boot 4commons-compressAffected
Red Hat build of Debezium 2commons-compressNot affected
Red Hat Build of Keycloakcommons-compressNot affected
Red Hat build of OptaPlanner 8commons-compressNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2264989commons-compress: OutOfMemoryError unpacking broken Pack200 file

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.

CVSS3: 5.5
nvd
почти 2 года назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.

msrc
5 месяцев назад

Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

CVSS3: 5.5
debian
почти 2 года назад

Allocation of Resources Without Limits or Throttling vulnerability in ...

CVSS3: 5.5
github
почти 2 года назад

Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

5.5 Medium

CVSS3