Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAB8XdGAyo6cf23fn-iWRaHB3Kt0qvw3H=JqG02jqW0Buf6fzpg@mail.gmail.com>
Date: Thu, 18 Jul 2024 16:52:29 +0100
From: Colm O hEigeartaigh <coheigea@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2024-41172: Unrestricted memory consumption in CXF HTTP clients

CVE-2024-41172: Unrestricted memory consumption in CXF HTTP clients

Severity: low

Affected versions:

- Apache CXF 3.6.0, 4.0.0 before 3.6.4, 4.0.5

Description:

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower
versions are not impacted), a CXF HTTP client conduit may prevent
HTTPClient instances from being garbage collected and it is possible
that memory consumption will continue to increase, eventually causing
the application to run  out of memory

References:

https://cxf.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-41172

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.