Vulnerability Details CVE-2024-47554
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.5%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2024-47554
-
cpe:2.3:a:apache:commons_io:2.0
-
cpe:2.3:a:apache:commons_io:2.0.1
-
cpe:2.3:a:apache:commons_io:2.1
-
cpe:2.3:a:apache:commons_io:2.10.0
-
cpe:2.3:a:apache:commons_io:2.11.0
-
cpe:2.3:a:apache:commons_io:2.12.0
-
cpe:2.3:a:apache:commons_io:2.13.0
-
cpe:2.3:a:apache:commons_io:2.2
-
cpe:2.3:a:apache:commons_io:2.3
-
cpe:2.3:a:apache:commons_io:2.4
-
cpe:2.3:a:apache:commons_io:2.5
-
cpe:2.3:a:apache:commons_io:2.6
-
cpe:2.3:a:apache:commons_io:2.7
-
cpe:2.3:a:apache:commons_io:2.8.0
-
cpe:2.3:a:apache:commons_io:2.9.0
-
cpe:2.3:a:netapp:active_iq_unified_manager:-
-
cpe:2.3:a:netapp:bluexp:-
-
cpe:2.3:a:netapp:e-series_santricity_unified_manager:-
-
cpe:2.3:a:netapp:e-series_santricity_web_services_proxy:-
-
cpe:2.3:a:netapp:ontap_tools:10
-
cpe:2.3:a:netapp:ontap_tools:9
-
cpe:2.3:a:netapp:santricity_storage_plugin:-
-
cpe:2.3:a:netapp:snapcenter:-