A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
History

Sat, 15 Feb 2025 01:30:00 +0000

Type Values Removed Values Added
References

Tue, 11 Feb 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache cxf
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache cxf

Wed, 22 Jan 2025 02:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Tue, 21 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 10:45:00 +0000

Type Values Removed Values Added
References

Tue, 21 Jan 2025 09:45:00 +0000

Type Values Removed Values Added
Description A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
Title Apache CXF: Denial of Service vulnerability with temporary files
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-02-15T00:10:35.436Z

Reserved: 2025-01-13T10:54:19.489Z

Link: CVE-2025-23184

cve-icon Vulnrichment

Updated: 2025-02-15T00:10:35.436Z

cve-icon NVD

Status : Modified

Published: 2025-01-21T10:15:08.110

Modified: 2025-02-15T01:15:11.010

Link: CVE-2025-23184

cve-icon Redhat

Severity : Low

Publid Date: 2025-01-21T09:35:37Z

Links: CVE-2025-23184 - Bugzilla