CVE-2025-32952

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 770

Summary

CVE-2025-32952 affects versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4 of Jmix, a popular set of libraries and tools for Spring Boot application development. The local file storage implementation in these versions fails to impose size limits on uploaded files, enabling attackers to upload excessively large files. This vulnerability could potentially cause the server to run out of space and respond with an HTTP 500 error, leading to a denial of service. The issue has been mitigated in versions 1.6.2 and 2.4.0 of Jmix. A workaround is available on the Jmix documentation website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share