First published: Thu Oct 03 2024(Updated: )
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Commons IO | <2.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2316271 is considered high due to the potential for excessive CPU resource consumption.
To fix REDHAT-BUG-2316271, users should upgrade Apache Commons IO to version 2.14.0 or later.
Apache Commons IO versions from 2.0 up to, but not including, 2.14.0 are affected by REDHAT-BUG-2316271.
REDHAT-BUG-2316271 is classified as an Uncontrolled Resource Consumption vulnerability.
The org.apache.commons.io.input.XmlStreamReader class is associated with REDHAT-BUG-2316271.