CVE-2024-47554: Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Other sources
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
— GitHub
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47554?
CVE-2024-47554 has a severity rating classified as a denial of service vulnerability that poses significant risk to affected systems.
Which versions of Apache Commons IO are affected by CVE-2024-47554?
Apache Commons IO versions from 2.0 up to and including 2.14.0 are affected by CVE-2024-47554.
How do I fix CVE-2024-47554?
To fix CVE-2024-47554, upgrade to version 2.14.0 of Apache Commons IO or later.
What impact does CVE-2024-47554 have on IBM Concert Software?
CVE-2024-47554 affects IBM Concert Software versions up to and including 1.0.3, potentially leading to denial of service.
Can CVE-2024-47554 be exploited remotely?
Yes, CVE-2024-47554 can be exploited remotely by sending specially crafted inputs to the vulnerable Apache Commons IO components.