First published: Thu Jul 18 2024(Updated: )
Apache CXF is vulnerable to a denial of service, caused by a memory consumption flaw in CXF HTTP clients when preventing HTTPClient instances from being garbage collected. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache CXF | >=3.6.0<3.6.4 | |
Apache CXF | >=4.0.0<4.0.5 | |
maven/org.apache.cxf:cxf-rt-transports-http | >=3.6.0<3.6.4 | 3.6.4 |
maven/org.apache.cxf:cxf-rt-transports-http | >=4.0.0<4.0.5 | 4.0.5 |
IBM Security Verify Governance | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.