CVE-2024-54016

CWE-4094 documents4 sources
Severity
4.3MEDIUM
EPSS
0.4%
top 39.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20

Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): through <=2.2.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDapache/seata2.0.02.3.0
Mavenorg.apache.seata:seata-parent2.0.02.3.0

🔴Vulnerability Details

3
OSV
Apache Seata Vulnerable to Data Amplification2025-03-20
GHSA
Apache Seata Vulnerable to Data Amplification2025-03-20
CVEList
compression bomb attack in Apache Seata Server2025-03-20
CVE-2024-54016 (MEDIUM CVSS 4.3) | Improper Handling of Highly Compres | cvebase.io