Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-41172

Опубликовано: 19 июл. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory

A memory consumption flaw was found in Apache CXF. This issue may allow a CXF HTTP client conduit to prevent HTTPClient instances from being garbage collected, eventually causing the application to run out of memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3org.apache.cxf/cxf-rt-transports-httpNot affected
Red Hat build of Apache Camel for Spring Boot 4org.apache.cxf/cxf-rt-transports-httpAffected
Red Hat Build of Keycloakorg.apache.cxf/cxf-rt-transports-httpNot affected
Red Hat build of Quarkusorg.apache.cxf/cxf-rt-transports-httpWill not fix
Red Hat Fuse 7org.apache.cxf/cxf-rt-transports-httpNot affected
Red Hat Integration Camel K 1org.apache.cxf/cxf-rt-transports-httpNot affected
Red Hat JBoss Data Grid 7org.apache.cxf/cxf-rt-transports-httpNot affected
Red Hat JBoss Enterprise Application Platform 7org.apache.cxf/cxf-rt-transports-httpNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.apache.cxf/cxf-rt-transports-httpNot affected
Red Hat Process Automation 7org.apache.cxf/cxf-rt-transports-httpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2298829apache: cxf: org.apache.cxf:cxf-rt-transports-http: unrestricted memory consumption in CXF HTTP clients

EPSS

Процентиль: 75%
0.00889
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory

CVSS3: 3.7
github
больше 1 года назад

Apache CXF allows unrestricted memory consumption in CXF HTTP clients

CVSS3: 3.5
fstec
больше 1 года назад

Уязвимость HTTP-клиента каркаса для веб-сервисов Apache CXF, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 75%
0.00889
Низкий

7.5 High

CVSS3