A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
References
Configurations
Configuration 1 (hide)
|
History
15 Feb 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Feb 2025, 16:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.apache.org/thread/lfs8l63rnctnj2skfrxyys7v8fgnt122 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2025/01/20/3 - Mailing List | |
CPE | cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo | |
Summary |
|
|
First Time |
Apache
Apache cxf |
21 Jan 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-21 10:15
Updated : 2025-02-15 01:15
NVD link : CVE-2025-23184
Mitre link : CVE-2025-23184
CVE.ORG link : CVE-2025-23184
JSON object : View
Products Affected
apache
- cxf
CWE