CVE-2024-47554
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Oct 3, 2024
Updated: Jan 31, 2025
CWE ID 400
Summary
CVE-2024-47554 is an Uncontrolled Resource Consumption vulnerability affecting the org.apache.commons.io.input.XmlStreamReader class in Apache Commons IO. Maliciously crafted input can cause this class to excessively consume CPU resources. This issue impacts Apache Commons IO versions from 2.0 to 2.13.9. To mitigate this risk, users are advised to upgrade to version 2.14.0 or later, which includes the necessary fixes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Apache Commons IO
Affected Vendors
- Apache Software Foundation