CVE-2024-47554 Information
Oct 04, 2024
cve
Description
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later which fixes the issue.
Reference
https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1
Share on: