CVE-2024-47554

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Oct 3, 2024
Updated: Jan 31, 2025
CWE ID 400

Summary

CVE-2024-47554 is an Uncontrolled Resource Consumption vulnerability affecting the org.apache.commons.io.input.XmlStreamReader class in Apache Commons IO. Maliciously crafted input can cause this class to excessively consume CPU resources. This issue impacts Apache Commons IO versions from 2.0 to 2.13.9. To mitigate this risk, users are advised to upgrade to version 2.14.0 or later, which includes the necessary fixes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache Commons IO

Affected Vendors

  • Apache Software Foundation