Apache CXF
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*
- < 3.5.10
- >= 3.6.0, < 3.6.5
- >= 4.0.0, < 4.0.6
A denial-of-service vulnerability has been identified in Apache CXF versions prior to 3.5.10, 3.6.0 prior to 3.6.5, and 4.0.0 prior to 4.0.6. In certain edge cases, instances of CachedOutputStream may not be properly closed. If these instances are backed by temporary files, they can accumulate and potentially fill up the file system, affecting both server and client environments.
Exploitation of this vulnerability can lead to a denial-of-service condition, causing system resources to be exhausted and potentially disrupting normal operations.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.