CVE-2025-32952
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-32952 affects versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4 of Jmix, a popular set of libraries and tools for Spring Boot application development. The local file storage implementation in these versions fails to impose size limits on uploaded files, enabling attackers to upload excessively large files. This vulnerability could potentially cause the server to run out of space and respond with an HTTP 500 error, leading to a denial of service. The issue has been mitigated in versions 1.6.2 and 2.4.0 of Jmix. A workaround is available on the Jmix documentation website.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Jmix