Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-47554

Опубликовано: 03 окт. 2024
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

A vulnerability was found in the Apache Commons IO component in the org.apache.commons.io.input.XmlStreamReader class. Excessive CPU resource consumption can lead to a denial of service when an untrusted input is processed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2commons-ioFix deferred
Cryostat 3commons-ioFix deferred
Cryostat 4commons-ioFix deferred
Red Hat AMQ Broker 7commons-ioNot affected
Red Hat AMQ Clientscommons-ioFix deferred
Red Hat build of Apache Camel 4 for Quarkus 3quarkus-cxf-bomFix deferred
Red Hat build of Apache Camel for Spring Boot 4commons-ioFix deferred
Red Hat build of Apache Camel - HawtIO 4commons-ioFix deferred
Red Hat build of Apicurio Registry 2commons-ioFix deferred
Red Hat build of Apicurio Registry 3commons-ioFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2316271apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader

EPSS

Процентиль: 39%
0.00173
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 1 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
nvd
больше 1 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS3: 4.3
msrc
больше 1 года назад

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

CVSS3: 4.3
debian
больше 1 года назад

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. ...

suse-cvrf
больше 1 года назад

Security update for apache-commons-io

EPSS

Процентиль: 39%
0.00173
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2024-47554