https://seclists.org/oss-sec/2024/q4/2: CVE-2024-47554: Apache Commons IO: Possible denial of service attack on untrusted input to XmlStamader
Published Oct 3, 2024
·Updated
Affected Software
1 affected component
Apache Commons IO<2.14.0
Frequently Asked Questions
1
What is the severity of CVE-2024-47554?
The severity of CVE-2024-47554 is low.
2
Which versions of Apache Commons IO are affected by CVE-2024-47554?
Apache Commons IO versions before 2.14.0 are affected by CVE-2024-47554.
3
What type of vulnerability is CVE-2024-47554?
CVE-2024-47554 is an uncontrolled resource consumption vulnerability.
4
How do I fix CVE-2024-47554?
To fix CVE-2024-47554, you should upgrade Apache Commons IO to version 2.14.0 or later.
5
What does CVE-2024-47554 affect in Apache Commons IO?
CVE-2024-47554 affects the org.apache.commons.io.input.XmlStreamReader class in Apache Commons IO.