VDB
Sign up
HIGH7.5

GHSA-fh5r-crhr-qrrq

Apache CXF: Denial of Service vulnerability with temporary files

Quick fix

GHSA-fh5r-crhr-qrrq — org.apache.cxf:cxf-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.5.10</version> for org.apache.cxf:cxf-core

Details

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.cxf:cxf-core
Introduced in: 0Fixed in: 3.5.10
Fix# pom.xml: bump <version>3.5.10</version> for org.apache.cxf:cxf-core
Maven/org.apache.cxf:cxf-core
Introduced in: 3.6.0Fixed in: 3.6.5
Fix# pom.xml: bump <version>3.6.5</version> for org.apache.cxf:cxf-core
Maven/org.apache.cxf:cxf-core
Introduced in: 4.0.0Fixed in: 4.0.6
Fix# pom.xml: bump <version>4.0.6</version> for org.apache.cxf:cxf-core

References