Логотип exploitDog
bind:CVE-2025-48795
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-48795

Количество 4

Количество 4

redhat логотип

CVE-2025-48795

около 1 месяца назад

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF to encrypt temporary files to prevent sensitive credentials from being cached unencrypted on the local filesystem, however this bug means that the cached files are written out to logs unencrypted. Users are recommended to upgrade to versions 3.5.11, 3.6.6, 4.0.7 or 4.1.1, which fixes this issue.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2025-48795

около 1 месяца назад

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF to encrypt temporary files to prevent sensitive credentials from being cached unencrypted on the local filesystem, however this bug means that the cached files are written out to logs unencrypted. Users are recommended to upgrade to versions 3.5.11, 3.6.6, 4.0.7 or 4.1.1, which fixes this issue.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-36wv-v2qp-v4g4

около 1 месяца назад

Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged

CVSS3: 5.6
EPSS: Низкий
fstec логотип

BDU:2025-09490

около 1 месяца назад

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-48795

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF to encrypt temporary files to prevent sensitive credentials from being cached unencrypted on the local filesystem, however this bug means that the cached files are written out to logs unencrypted. Users are recommended to upgrade to versions 3.5.11, 3.6.6, 4.0.7 or 4.1.1, which fixes this issue.

CVSS3: 4.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-48795

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF to encrypt temporary files to prevent sensitive credentials from being cached unencrypted on the local filesystem, however this bug means that the cached files are written out to logs unencrypted. Users are recommended to upgrade to versions 3.5.11, 3.6.6, 4.0.7 or 4.1.1, which fixes this issue.

CVSS3: 5.6
0%
Низкий
около 1 месяца назад
github логотип
GHSA-36wv-v2qp-v4g4

Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged

CVSS3: 5.6
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2025-09490

Уязвимость каркаса для веб-сервисов Apache CXF, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.6
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу