CVE-2024-41172

CWE-401Memory Leak5 documents5 sources
Severity
7.5HIGH
EPSS
0.9%
top 24.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19

Description

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Mavenorg.apache.cxf:cxf-rt-transports-http4.0.04.0.5+1
NVDapache/cxf3.6.03.6.4+1
CVEListV5apache_software_foundation/apache_cxf3.6.0, 4.0.03.6.4, 4.0.5

🔴Vulnerability Details

3
OSV
Apache CXF allows unrestricted memory consumption in CXF HTTP clients2024-07-19
CVEList
Apache CXF: Unrestricted memory consumption in CXF HTTP clients2024-07-19
GHSA
Apache CXF allows unrestricted memory consumption in CXF HTTP clients2024-07-19

📋Vendor Advisories

1
Red Hat
apache: cxf: org.apache.cxf:cxf-rt-transports-http: unrestricted memory consumption in CXF HTTP clients2024-07-19
CVE-2024-41172 (HIGH CVSS 7.5) | In versions of Apache CXF before 3. | cvebase.io