跳转到帖子

Red Hat JBossEAP: Uncontrolled Resource Consumption (CVE-2025-23184)

recommended_posts

发布于
  • Members

Red Hat JBossEAP: Uncontrolled Resource Consumption (CVE-2025-23184)

Severity
5
CVSS
(AV:N/AC:H/Au:N/C:N/I:N/A:C)
Published
01/21/2025
Created
01/24/2025
Added
01/23/2025
Modified
02/03/2025

Description

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).. A flaw was found in Apache CXF. In some edge cases with large data stream caching, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system and trigger a denial of service.

Solution(s)

  • red-hat-jboss-eap-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2025-23184
  • CVE - 2025-23184
  • https://access.redhat.com/security/cve/CVE-2025-23184
  • https://bugzilla.redhat.com/show_bug.cgi?id=2339095
  • https://lists.apache.org/thread/lfs8l63rnctnj2skfrxyys7v8fgnt122
  • 查看数 710
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…