- Description
- A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
- Source
- security@apache.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- security@apache.org
- CWE-400
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
برای محصول Apache CXF که یک فریمورک برای ساخت Web service می باشد ، آسیب پذیری از نوع DOS و با کد شناسایی CVE-2025-23184 منتشر شده است. نسخه های قبل از 3.5.10 و نسخه های بین 3.6.0 تا 3.6.5 و نسخه های قبل از 4.0.6 دارای این آسیب پذیری می باشند. https://t.co/Poz3aKY03t https://t.c
@AmirHossein_sec
30 Jan 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-23184 A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances … https://t.co/Ku4nNA6mqk
@CVEnew
21 Jan 2025
405 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-23184 CVE-2025-23184 https://t.co/tVnKOrxqEo
@VulmonFeeds
20 Jan 2025
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-23184: Apache CXF: Denial of Service vulnerability with temporary files https://t.co/6Er5bcKKQd In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients)
@oss_security
20 Jan 2025
249 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F551B7C-101F-4859-B2CD-C9F76D7C61F2",
"versionEndExcluding": "3.5.10"
},
{
"criteria": "cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A581BA3B-93A1-4AED-AAF7-041EFC91EFE7",
"versionEndExcluding": "3.6.5",
"versionStartIncluding": "3.6.0"
},
{
"criteria": "cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3533A0DD-FA20-4427-A9A3-3FAFFF37D5BF",
"versionEndExcluding": "4.0.6",
"versionStartIncluding": "4.0.0"
}
],
"operator": "OR"
}
]
}
]