REDHAT-BUG-2339095: Low severity Apache CXF vulnerability
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 3.5.10 - Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 3.6.5 - Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 4.0.6
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2339095?
The severity of REDHAT-BUG-2339095 is classified as a potential denial of service vulnerability.
How do I fix REDHAT-BUG-2339095?
To fix REDHAT-BUG-2339095, upgrade Apache CXF to versions 3.5.10, 3.6.5, or 4.0.6 or newer.
What versions are affected by REDHAT-BUG-2339095?
REDHAT-BUG-2339095 affects versions of Apache CXF before 3.5.10, 3.6.5, and 4.0.6.
What is the impact of REDHAT-BUG-2339095?
The impact of REDHAT-BUG-2339095 is that it may lead to file system exhaustion by not closing CachedOutputStream instances properly.
Is REDHAT-BUG-2339095 applicable to both servers and clients?
Yes, REDHAT-BUG-2339095 applies to both server and client implementations of Apache CXF.