CVE-2024-47554 is an Uncontrolled Resource Consumption vulnerability in Apache Commons IO versions prior to 2.14.0, specifically affecting the org.apache.commons.io.input.XmlStreamReader class. Maliciously crafted input can cause excessive CPU consumption, impacting products from Apache and NetApp. Rated Medium (CVSS 4.3), this vulnerability requires user interaction (UI:R) and could lead to a denial of service (A:L), but does not compromise confidentiality or integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.14.0CPE matchmatch criteria | cpe:2.3:a:apache:commons_io:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:bluexp:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-47554
Dec 10, 2024CVE-2024-47554
Nov 12, 2024Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Oct 8, 2024Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Oct 3, 2024apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader
Oct 3, 2024