Apache CXF: Denial of Service vulnerability with temporary files
Moderate severity
GitHub Reviewed
Published
Jan 21, 2025
to the GitHub Advisory Database
•
Updated Jan 21, 2025
Package
Affected versions
< 3.5.10
>= 3.6.0, < 3.6.5
>= 4.0.0, < 4.0.6
Patched versions
3.5.10
3.6.5
4.0.6
Description
Published by the National Vulnerability Database
Jan 21, 2025
Published to the GitHub Advisory Database
Jan 21, 2025
Last updated
Jan 21, 2025
Reviewed
Jan 21, 2025
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
References