A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-01-21 10:15
Updated : 2025-02-15 01:15
NVD link : CVE-2025-23184
Mitre link : CVE-2025-23184
CVE.ORG link : CVE-2025-23184
JSON object : View
Products Affected
apache
- cxf
CWE
