A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
Metrics
Affected Vendors & Products
References
History
Sat, 15 Feb 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 11 Feb 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache cxf |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache cxf |
Wed, 22 Jan 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 21 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 21 Jan 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 21 Jan 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients). | |
Title | Apache CXF: Denial of Service vulnerability with temporary files | |
Weaknesses | CWE-400 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-15T00:10:35.436Z
Reserved: 2025-01-13T10:54:19.489Z
Link: CVE-2025-23184

Updated: 2025-02-15T00:10:35.436Z

Status : Modified
Published: 2025-01-21T10:15:08.110
Modified: 2025-02-15T01:15:11.010
Link: CVE-2025-23184
