Описание
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
A flaw was found in Apache CXF. In some edge cases with large data stream caching, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system and trigger a denial of service.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | org.apache.cxf/cxf-core | Fix deferred | ||
Red Hat build of Apache Camel 4 for Quarkus 3 | org.apache.cxf/cxf-core | Fix deferred | ||
Red Hat build of Apache Camel for Spring Boot 4 | org.apache.cxf/cxf-core | Fix deferred | ||
Red Hat Build of Keycloak | org.apache.cxf/cxf-core | Fix deferred | ||
Red Hat build of Quarkus | org.apache.cxf/cxf-core | Fix deferred | ||
Red Hat Fuse 7 | org.apache.cxf/cxf-core | Out of support scope | ||
Red Hat Integration Camel K 1 | org.apache.cxf/cxf-core | Fix deferred | ||
Red Hat JBoss Data Grid 7 | org.apache.cxf/cxf-core | Fix deferred | ||
Red Hat JBoss Enterprise Application Platform 8 | org.jboss.eap-jboss-eap-xp | Fix deferred | ||
Red Hat JBoss Enterprise Application Platform Expansion Pack | org.apache.cxf/cxf-core | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
Apache CXF: Denial of Service vulnerability with temporary files
Уязвимость функции CachedOutputStream каркаса для веб-сервисов Apache CXF, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
3.7 Low
CVSS3