Описание
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
A memory consumption flaw was found in Apache CXF. This issue may allow a CXF HTTP client conduit to prevent HTTPClient instances from being garbage collected, eventually causing the application to run out of memory.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 3 | org.apache.cxf/cxf-rt-transports-http | Not affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | org.apache.cxf/cxf-rt-transports-http | Affected | ||
| Red Hat Build of Keycloak | org.apache.cxf/cxf-rt-transports-http | Not affected | ||
| Red Hat build of Quarkus | org.apache.cxf/cxf-rt-transports-http | Will not fix | ||
| Red Hat Fuse 7 | org.apache.cxf/cxf-rt-transports-http | Not affected | ||
| Red Hat Integration Camel K 1 | org.apache.cxf/cxf-rt-transports-http | Not affected | ||
| Red Hat JBoss Data Grid 7 | org.apache.cxf/cxf-rt-transports-http | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | org.apache.cxf/cxf-rt-transports-http | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.apache.cxf/cxf-rt-transports-http | Not affected | ||
| Red Hat Process Automation 7 | org.apache.cxf/cxf-rt-transports-http | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
Apache CXF allows unrestricted memory consumption in CXF HTTP clients
Уязвимость HTTP-клиента каркаса для веб-сервисов Apache CXF, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3